CVE-2025-48980: Medium severity Brave Brave Browser vulnerability
In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on a cross-site navigation using this method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48980?
CVE-2025-48980 is considered to have a medium severity level due to its potential for impacting user privacy through improper handling of SameSite cookies.
How do I fix CVE-2025-48980?
To fix CVE-2025-48980, users should update their Brave Browser to version 1.83.10 or later, where this vulnerability has been addressed.
What versions of Brave Browser are affected by CVE-2025-48980?
Brave Browser Desktop versions prior to 1.83.10 are affected by CVE-2025-48980.
How does CVE-2025-48980 affect SameSite cookie handling?
CVE-2025-48980 allows SameSite=Strict cookies to be sent on cross-site navigation when using the 'Open Link in Split View' feature, which violates the intended cookie security model.
Is it safe to use Brave Browser with CVE-2025-48980 present?
Using Brave Browser versions prior to 1.83.10 may pose a risk to user privacy, so it is advisable to update immediately to mitigate this vulnerability.