The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. A malicious website may exfiltrate data cross-origin.
2025-05-12T22:15:21.627
2025-05-27T13:57:20.370
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apple | safari | < 18.5 | Yes |
Operating System | apple | ipados | < 18.5 | Yes |
Operating System | apple | iphone_os | < 18.5 | Yes |
Operating System | apple | macos | < 15.5 | Yes |
Operating System | apple | tvos | < 18.5 | Yes |
Operating System | apple | visionos | < 2.5 | Yes |
Operating System | apple | watchos | < 11.5 | Yes |