5.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Description
This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content may lead to unexpected URL redirection.
Basic Information
ID
CVE-2025-31254
Source
apple
Published
Sep 15, 2025 at 22:34
Modified
Sep 16, 2025 at 15:15
Affected Product
Vendor
Apple
Product
iOS and iPadOS
Version
unspecified
Affected Versions
Apple iOS and iPadOS unspecified
Apple Safari unspecified
Apple Safari unspecified