CVE-2025-43526
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-12-17

Last updated on: 2026-04-02

Assigner: Apple Inc.

Description
This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-17
Last Modified
2026-04-02
Generated
2026-06-16
AI Q&A
2025-12-17
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
apple safari to 26.2 (exc)
apple macos to 26.2 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability involves improper URL validation in macOS Tahoe and Safari, where web content opened via a file URL on a Mac with Lockdown Mode enabled may be able to access Web APIs that should be restricted. This issue was fixed by improving URL validation in macOS Tahoe 26.2 and Safari 26.2.

Impact Analysis

The vulnerability could allow web content opened from file URLs to use Web APIs that are supposed to be restricted under Lockdown Mode, potentially leading to unauthorized access or actions that compromise system security or user privacy.

Mitigation Strategies

Update your macOS to version Tahoe 26.2 and Safari to version 26.2, as these versions include the fix with improved URL validation. Additionally, ensure that Lockdown Mode is enabled on your Mac to help restrict web content opened via file URLs.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-43526. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart