PT-2025-26717 · Apple · Apple Macos

Published

2025-05-12

·

Updated

2025-11-23

·

CVE-2025-31266

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Safari versions prior to 18.5 macOS Sequoia versions prior to 15.5
Description A flaw allows a website to potentially spoof the domain name displayed in a pop-up window's title bar. This occurs due to improved truncation when displaying the fully qualified domain name.
Recommendations Update Safari to version 18.5. Update macOS Sequoia to version 15.5.

Fix

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

CVE-2025-31266

Affected Products

Apple Macos