Vulnerabilities (Page 57)

Insecurely Configured File Provide Exposes Brave's Cookie Database

Brave when configuring its File Provider exposes all files form its public and private directory. This means an app could trigger a download a Brave’s cookie database by making a request to the content:// url for it and have it downloaded into the Downloads folder where any app could read it.