In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on a cross-site navigation using this method.
                
            Metrics
Affected Vendors & Products
Advisories
    No advisories yet.
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        | Link | Providers | 
|---|---|
| https://hackerone.com/reports/3253725 |     | 
History
                    Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Brave Brave brave Brave brave Browser Brave browser | |
| Vendors & Products | Brave Brave brave Brave brave Browser Brave browser | 
Thu, 30 Oct 2025 23:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on a cross-site navigation using this method. | |
| References |  | |
| Metrics | cvssV3_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-10-30T23:29:44.075Z
Reserved: 2025-05-29T15:00:04.773Z
Link: CVE-2025-48980
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Received
Published: 2025-10-31T00:15:36.327
Modified: 2025-10-31T00:15:36.327
Link: CVE-2025-48980
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    Updated: 2025-10-31T10:13:10Z