The issue was addressed with improved checks. This issue is fixed in tvOS 26.1, watchOS 26.1, macOS Tahoe 26.1, iOS 26.1 and iPadOS 26.1, Safari 26.1, visionOS 26.1. A malicious website may exfiltrate data cross-origin.
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "26.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "26.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "26.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "26.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "26.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "26.1"
}
]
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-43480.json"