On most desktop platforms, Brave Browser versions 1.70.x...
Moderate severity
Unreviewed
Published
Jan 21, 2025
to the GitHub Advisory Database
•
Updated Jan 21, 2025
Description
Published by the National Vulnerability Database
Jan 21, 2025
Published to the GitHub Advisory Database
Jan 21, 2025
Last updated
Jan 21, 2025
On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-provided file selector dialog when a site prompts the user to upload or download a file. However the origin was not correctly inferred in some cases. When combined with an open redirector vulnerability on a trusted site, this could allow a malicious site to initiate a download whose origin in the file select dialog appears as the trusted site which initiated the redirect.
References