Vulnerability

Brave Browser Vulnerability Let Malicious Website Mimic as Legitimate One

A recently identified vulnerability in the Brave browser has raised significant security concerns for its users. The issue, tracked as CVE-2025-23086, affects desktop versions of Brave from 1.70.x to 1.73.x. 

It involves a flaw in how the browser displays the origin of a site in the file selector dialog during file upload or download prompts. 

This vulnerability could allow malicious websites to pose as trusted domains, potentially deceiving users into downloading harmful files.

Overview of the Vulnerability

The vulnerability stems from Brave’s feature that displays the origin of a site in the operating system’s file selector dialog. 

This feature is intended to enhance user awareness of a site’s legitimacy when interacting with file uploads or downloads. However, in certain scenarios, the origin was not correctly inferred.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

When combined with an open redirect vulnerability on a trusted site, attackers could exploit this flaw to make a malicious site appear as though it originated from the trusted domain in the file selector dialog.

An open redirect vulnerability occurs when a legitimate website allows user-controlled input to redirect users to external URLs without sufficient validation. 

By chaining this with Brave’s origin misrepresentation issue, attackers can craft scenarios where users unknowingly interact with malicious sites disguised as trustworthy ones.

This vulnerability significantly undermines user trust and security by enabling phishing attacks and malware distribution. Users could be tricked into downloading files or sharing sensitive information under the assumption they are interacting with a legitimate site.

The vulnerability was disclosed to Brave Software by the bug hunter, Syarif Muhammad Sajjad. 

Affected Versions

  • Vulnerable: Brave Desktop Browser versions up to 1.74.47.
  • Fixed: Version 1.74.48 and later.

Brave Software has addressed this issue in version 1.74.48 by correcting how site origins are displayed in file selector dialogs and improving validation mechanisms for open redirects. 

Users are advised to remain cautious when downloading files, even from seemingly trusted sources, and to always verify the authenticity of download prompts and file origins. 

Enabling automatic updates for Brave Browser can help ensure timely protection against newly discovered vulnerabilities.

Integrating Application Security into Your CI/CD Workflows Using Jenkins & Jira -> Free Webinar

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago