CVE-2025-43526
17.12.2025, 21:16
This issue was addressed with improved URL validation. This issue is fixed in macOS Tahoe 26.2, Safari 26.2. On a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted.
| Vendor | Product | Version |
|---|---|---|
| apple | safari | 𝑥 < 26.2 |
| apple | macos | 𝑥 < 26.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
Vulnerability Media Exposure