cbcvebase.
CVE-2025-43526
published 2025-12-17

CVE-2025-43526: This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac with Lockdown Mode enabled, web content…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted.

Affected

4 ranges
VendorProductVersion rangeFixed in
applemacos< 26.226.2
applemacos_tahoe
applesafari< 26.226.2
applesafari