Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-43356


The issue was addressed with improved handling of caches. This issue is fixed in Safari 26, tvOS 26, watchOS 26, iOS 26 and iPadOS 26, visionOS 26, iOS 18.7 and iPadOS 18.7. A website may be able to access sensor information without user consent.


Published

2025-09-15T23:15:37.530

Last Modified

2025-11-04T22:16:15.147

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apple safari < 26.0 Yes
Operating System apple ipados < 18.7 Yes
Operating System apple iphone_os < 18.7 Yes
Operating System apple macos < 26.0 Yes
Operating System apple tvos < 26.0 Yes
Operating System apple visionos < 26.0 Yes
Operating System apple watchos < 26.0 Yes

References