PT-2025-51902 · Apple · Safari+1

Andreas Jaegersberger

+1

·

Published

2025-12-12

·

Updated

2025-12-21

·

CVE-2025-43526

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions macOS versions prior to Tahoe 26.2 Safari versions prior to 26.2
Description A flaw exists due to improved URL validation. Specifically, on a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted.
Recommendations Update to macOS Tahoe 26.2. Update to Safari 26.2.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-43526

Affected Products

Apple Macos
Safari