CVE-2025-31205

Name
CVE-2025-31205
Description
The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. A malicious website may exfiltrate data cross-origin.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
product-security@apple.com https://support.apple.com/en-us/122404
product-security@apple.com https://support.apple.com/en-us/122716
product-security@apple.com https://support.apple.com/en-us/122719
product-security@apple.com https://support.apple.com/en-us/122720
product-security@apple.com https://support.apple.com/en-us/122721
product-security@apple.com https://support.apple.com/en-us/122722
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/May/10
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/May/12
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/May/13
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/May/5
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/May/7
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/06/msg00016.html

Match rules

CPE URI Source package Min version Max version
tvos >= unspecified < 18.5
macos >= unspecified < 15.5
ios-and-ipados >= unspecified < 18.5
visionos >= unspecified < 2.5
watchos >= unspecified < 11.5
safari >= unspecified < 18.5
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* safari >= None < 18.5
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* ipados >= None < 18.5
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* iphone_os >= None < 18.5
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* macos >= None < 15.5
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* tvos >= None < 18.5
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* visionos >= None < 2.5
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* watchos >= None < 11.5

Vulnerable and fixed packages

Source package Branch Version Maintainer Status