CVE-2025-43480
published 2025-11-04CVE-2025-43480: The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS…
PriorityP340high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
EPSS
0.45%
36.2th percentile
The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious website may exfiltrate data cross-origin.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_26.1_and_ipados | — | — |
| apple | ios_and_ipados | < 26.1 | 26.1 |
| apple | ipados | < 26.1 | 26.1 |
| apple | iphone_os | < 26.1 | 26.1 |
| apple | macos | < 26.1 | 26.1 |
| apple | macos_tahoe | — | — |
| apple | safari | < 26.1 | 26.1 |
| apple | safari | — | — |
| apple | tvos | < 26.1 | 26.1 |
| apple | tvos | — | — |
| apple | visionos | < 26.1 | 26.1 |
| apple | visionos | — | — |
| apple | watchos | < 26.1 | 26.1 |
| apple | watchos | — | — |
| debian | webkit2gtk | < webkit2gtk 2.46.0-2~deb12u1 (bookworm) | webkit2gtk 2.46.0-2~deb12u1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.46.0-2~deb12u1 (bookworm) | webkit2gtk 2.46.0-2~deb12u1 (bookworm) |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
webkitgtk: A malicious website may exfiltrate data cross-origin
vendor_redhat·2025-11-20·CVSS 8.1
CVE-2025-43480 [HIGH] CWE-200 webkitgtk: A malicious website may exfiltrate data cross-origin
webkitgtk: A malicious website may exfiltrate data cross-origin
The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious website may exfiltrate data cross-origin.
A flaw was found in WebKitGTK. A malicious website may exfiltrate data cross-origin due to improper checks.
Statement: To exploit this issue, an attacker needs to trick a user into visiting a malicious website, potentially exposing sensitive information. Due to this reason, this flaw has been rated with a moderate severity.
Mitigation: Do not visit untrusted websites. Also, do not process or load untrusted web content with WebKitGTK.
In Red Hat Enterprise Linux 7, the following packages require WebKitGTK4:
Apple
CVE-2025-43480: Safari 26.1
vendor_apple·2025-11-03·CVSS 8.1
CVE-2025-43480 [HIGH] CVE-2025-43480: Safari 26.1
Apple Security Update: About the security content of Safari 26.1
Product: Safari
Version: 26.1
CVE: CVE-2025-43480
Component: WebKit
Impact: A malicious website may exfiltrate data cross-origin
Description: The issue was addressed with improved checks.
Apple
CVE-2025-43480: watchOS 26.1
vendor_apple·2025-11-03·CVSS 8.1
CVE-2025-43480 [HIGH] CVE-2025-43480: watchOS 26.1
Apple Security Update: About the security content of watchOS 26.1
Product: watchOS
Version: 26.1
CVE: CVE-2025-43480
Component: WebKit
Impact: A malicious website may exfiltrate data cross-origin
Description: The issue was addressed with improved checks.
Apple
CVE-2025-43480: tvOS 26.1
vendor_apple·2025-11-03·CVSS 8.1
CVE-2025-43480 [HIGH] CVE-2025-43480: tvOS 26.1
Apple Security Update: About the security content of tvOS 26.1
Product: tvOS
Version: 26.1
CVE: CVE-2025-43480
Component: WebKit
Impact: A malicious website may exfiltrate data cross-origin
Description: The issue was addressed with improved checks.
Apple
CVE-2025-43480: iOS 26.1 and iPadOS 26.1
vendor_apple·2025-11-03·CVSS 8.1
CVE-2025-43480 [HIGH] CVE-2025-43480: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43480
Component: WebKit
Impact: A malicious website may exfiltrate data cross-origin
Description: The issue was addressed with improved checks.
Apple
CVE-2025-43480: visionOS 26.1
vendor_apple·2025-11-03·CVSS 8.1
CVE-2025-43480 [HIGH] CVE-2025-43480: visionOS 26.1
Apple Security Update: About the security content of visionOS 26.1
Product: visionOS
Version: 26.1
CVE: CVE-2025-43480
Component: WebKit
Impact: A malicious website may exfiltrate data cross-origin
Description: The issue was addressed with improved checks.
Apple
CVE-2025-43480: macOS Tahoe 26.1
vendor_apple·2025-11-03·CVSS 8.1
CVE-2025-43480 [HIGH] CVE-2025-43480: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43480
Component: WebKit
Impact: A malicious website may exfiltrate data cross-origin
Description: The issue was addressed with improved checks.
Debian
CVE-2025-43480: webkit2gtk - The issue was addressed with improved checks. This issue is fixed in Safari 26.1...
vendor_debian·2025·CVSS 8.1
CVE-2025-43480 [HIGH] CVE-2025-43480: webkit2gtk - The issue was addressed with improved checks. This issue is fixed in Safari 26.1...
The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious website may exfiltrate data cross-origin.
Scope: local
bookworm: resolved (fixed in 2.46.0-2~deb12u1)
bullseye: resolved (fixed in 2.46.0-1)
forky: resolved (fixed in 2.46.0-1)
sid: resolved (fixed in 2.46.0-1)
trixie: resolved (fixed in 2.46.0-1)
OSV
CVE-2025-43480: The issue was addressed with improved checks
osv·2025-11-04·CVSS 8.1
CVE-2025-43480 [HIGH] CVE-2025-43480: The issue was addressed with improved checks
The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious website may exfiltrate data cross-origin.
OSV
CVE-2025-43480: The issue was addressed with improved checks
osv·2025-11-04·CVSS 8.1
CVE-2025-43480 [HIGH] CVE-2025-43480: The issue was addressed with improved checks
The issue was addressed with improved checks. This issue is fixed in tvOS 26.1, watchOS 26.1, macOS Tahoe 26.1, iOS 26.1 and iPadOS 26.1, Safari 26.1, visionOS 26.1. A malicious website may exfiltrate data cross-origin.
GHSA
GHSA-wg34-qg7p-mhvv: The issue was addressed with improved checks
ghsa_unreviewed·2025-11-04
CVE-2025-43480 [HIGH] CWE-942 GHSA-wg34-qg7p-mhvv: The issue was addressed with improved checks
The issue was addressed with improved checks. This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvOS 26.1. A malicious website may exfiltrate data cross-origin.
No detection rules found.
No public exploits indexed.
2025-11-04
Published