CVE-2025-43526

Description

This issue was addressed with improved URL validation. This issue is fixed in macOS Tahoe 26.2, Safari 26.2. On a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.057

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in macOS Tahoe 26.2 (Software Update) (Auto Reboot)Mac
Multiple Vulnerabilities are affected in Apple Safari for MAC 26.1Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-613038macOS Tahoe 26.2 (Software Update) (Auto Reboot)
PATCH-613034Apple Safari for MAC (MacOS Sequoia) (26.2)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234