9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
This issue was addressed with improved URL validation. This issue is fixed in macOS Tahoe 26.2, Safari 26.2. On a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted.
AI Analysis
A vulnerability in Safari allows web content to use restricted Web APIs when opened via a file URL on a Mac with Lockdown Mode enabled.
Basic Information
ID
CVE-2025-43526
Source
apple
Published
Dec 17, 2025 at 20:46
Modified
Dec 18, 2025 at 19:19
Affected Product
Vendor
Apple
Product
Safari
Version
unspecified
Affected Versions
Apple Safari unspecified
Apple macOS unspecified
Apple macOS unspecified
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
Apple
Product
Safari
Version
unspecified