The issue was addressed with improved handling of caches. This issue is fixed in tvOS 26.1, watchOS 26.1, macOS Tahoe 26.1, iOS 26.1 and iPadOS 26.1, Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, visionOS 26.1. A website may exfiltrate image data cross-origin.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-11-04 02:15
Updated : 2025-12-17 21:15
NVD link : CVE-2025-43392
Mitre link : CVE-2025-43392
CVE.ORG link : CVE-2025-43392
JSON object : View
Products Affected
apple
- ipados
- iphone_os
- tvos
- visionos
- safari
- watchos
CWE
CWE-942
Permissive Cross-domain Security Policy with Untrusted Domains
