CVE-2025-43392

T

he issue was addressed with improved handling of caches. This issue is fixed in tvOS 26.1, watchOS 26.1, macOS Tahoe 26.1, iOS 26.1 and iPadOS 26.1, Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, visionOS 26.1. A website may exfiltrate image data cross-origin.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

17 Dec 2025, 21:15

Type Values Removed Values Added
References
  • () https://support.apple.com/en-us/125632 -
  • () https://support.apple.com/en-us/125634 -
  • () https://support.apple.com/en-us/125637 -
  • () https://support.apple.com/en-us/125638 -
  • () https://support.apple.com/en-us/125639 -
  • () https://support.apple.com/en-us/125640 -
Summary (en) The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. A website may exfiltrate image data cross-origin. (en) The issue was addressed with improved handling of caches. This issue is fixed in tvOS 26.1, watchOS 26.1, macOS Tahoe 26.1, iOS 26.1 and iPadOS 26.1, Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, visionOS 26.1. A website may exfiltrate image data cross-origin.

05 Nov 2025, 19:15

Type Values Removed Values Added
References
  • {'url': 'https://support.apple.com/en-us/125632', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': '[email protected]'}
  • {'url': 'https://support.apple.com/en-us/125637', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': '[email protected]'}
  • {'url': 'https://support.apple.com/en-us/125638', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': '[email protected]'}
  • {'url': 'https://support.apple.com/en-us/125639', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': '[email protected]'}
  • {'url': 'https://support.apple.com/en-us/125640', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': '[email protected]'}
  • () https://support.apple.com/en-us/125633 -
Summary (en) The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvOS 26.1. A website may exfiltrate image data cross-origin. (en) The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. A website may exfiltrate image data cross-origin.

05 Nov 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 4.3
CWE CWE-524 CWE-942

04 Nov 2025, 18:18

Type Values Removed Values Added
CPE cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
References () https://support.apple.com/en-us/125632 - () https://support.apple.com/en-us/125632 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/125637 - () https://support.apple.com/en-us/125637 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/125638 - () https://support.apple.com/en-us/125638 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/125639 - () https://support.apple.com/en-us/125639 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/125640 - () https://support.apple.com/en-us/125640 - Release Notes, Vendor Advisory
First Time Apple ipados
Apple watchos
Apple safari
Apple tvos
Apple
Apple visionos
Apple iphone Os

04 Nov 2025, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-524

04 Nov 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-04 02:15

Updated : 2025-12-17 21:15


NVD link : CVE-2025-43392

Mitre link : CVE-2025-43392

CVE.ORG link : CVE-2025-43392


JSON object : View

CWE
CWE-942

Permissive Cross-domain Policy with Untrusted Domains