CVE-2025-43392
Vulnerability Summary
Timeline
Description
The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A website may exfiltrate image data cross-origin.
CVSS Metrics
- v3.1•MEDIUM•Score: 4.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS Trends
Current EPSS score: 0.03%• Percentile: 9%
Techniques & Countermeasures
- CWE-942•Permissive Cross-domain Security Policy with Untrusted Domains
The product uses a web-client protection mechanism such as a Content Security Policy (CSP) or cross-domain policy file, but the policy includes untrusted domains with which the web client is allowed to communicate.
Affected Systems
- apple•ios and ipados
≥ unspecified, < 26.1 | ≥ unspecified, < 18.7 | < 18.7.2 | < 26.1
- apple•ipados
< 26.1
- apple•iphone_os
< 26.1
- apple•macos
≥ unspecified, < 26.1 | < 26.1
- apple•safari
≥ unspecified, < 26.1 | < 26.1
- apple•tvos
≥ unspecified, < 26.1 | < 26.1
- apple•visionos
≥ unspecified, < 26.1 | < 26.1
- apple•watchos
≥ unspecified, < 26.1 | < 26.1