Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-31266


A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be able to spoof the domain name in the title of a pop-up window.


Published

2025-11-21T22:16:19.743

Last Modified

2025-11-26T14:32:34.670

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-451

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apple safari < 18.5 Yes
Operating System apple macos < 15.5 Yes

References