CVE-2025-23086
Published: Jan 21, 2025
Modified: Mar 22, 2025
Description
On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-provided file selector dialog when a site prompts the user to upload or download a file. However the origin was not correctly inferred in some cases. When combined with an open redirector vulnerability on a trusted site, this could allow a malicious site to initiate a download whose origin in the file select dialog appears as the trusted site which initiated the redirect.
| Vendor | Product | Versions |
|---|---|---|
Brave | Desktop Browser | affected 1.74.48 - < 1.74.48unaffected 1.70.117 - < 1.70.117 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now