---
id: CVE-2025-48980
title: >-
  In Brave Browser Desktop versions prior to 1.83.10 that have the split view
  feature enabled, the "Open Link in Split View" context menu item did not
  respect the SameSite cookie attribute
summary: >-
  In Brave Browser Desktop versions prior to 1.83.10 that have the split view
  feature enabled, the "Open Link in Split View" context menu item did not
  respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would
  be sent o…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-565
published: '2025-10-31'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48980'
references:
  - url: 'https://hackerone.com/reports/3253725'
    label: support@hackerone.com
tags:
  - nvd
epss: 0.0033
epssPercentile: 0.24099
ingestedAt: '2026-10-07T21:54:14.908Z'
---

## Overview

In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on a cross-site navigation using this method.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
