PT-2025-51902 · Apple · Safari+1
Andreas Jaegersberger
+1
·
Published
2025-12-12
·
Updated
2025-12-21
·
CVE-2025-43526
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
macOS versions prior to Tahoe 26.2
Safari versions prior to 26.2
Description
A flaw exists due to improved URL validation. Specifically, on a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted.
Recommendations
Update to macOS Tahoe 26.2.
Update to Safari 26.2.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos
Safari