The issue was addressed with improved handling of caches. This issue is fixed in tvOS 26.1, watchOS 26.1, macOS Tahoe 26.1, iOS 26.1 and iPadOS 26.1, Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, visionOS 26.1. A website may exfiltrate image data cross-origin.
References
Configurations
Configuration 1 (hide)
|
History
17 Dec 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) The issue was addressed with improved handling of caches. This issue is fixed in tvOS 26.1, watchOS 26.1, macOS Tahoe 26.1, iOS 26.1 and iPadOS 26.1, Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, visionOS 26.1. A website may exfiltrate image data cross-origin. | |
| References |
|
05 Nov 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Summary | (en) The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. A website may exfiltrate image data cross-origin. |
05 Nov 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-942 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
04 Nov 2025, 18:18
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://support.apple.com/en-us/125632 - Release Notes, Vendor Advisory | |
| References | () https://support.apple.com/en-us/125637 - Release Notes, Vendor Advisory | |
| References | () https://support.apple.com/en-us/125638 - Release Notes, Vendor Advisory | |
| References | () https://support.apple.com/en-us/125639 - Release Notes, Vendor Advisory | |
| References | () https://support.apple.com/en-us/125640 - Release Notes, Vendor Advisory | |
| First Time |
Apple watchos
Apple tvos Apple iphone Os Apple safari Apple visionos Apple ipados Apple |
|
| CPE | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* |
04 Nov 2025, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-524 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
04 Nov 2025, 02:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-04 02:15
Updated : 2025-12-17 21:15
NVD link : CVE-2025-43392
Mitre link : CVE-2025-43392
CVE.ORG link : CVE-2025-43392
JSON object : View
Products Affected
apple
- watchos
- safari
- iphone_os
- visionos
- tvos
- ipados
CWE
CWE-942
Permissive Cross-domain Policy with Untrusted Domains
