CVE-2025-43229
This issue was addressed through improved state management. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to universal cross site scripting.
- Affected products
- Apple Macos
- Apple Safari
- < 18.6
- Apple Macos
- < 15.6
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 0.3% (24th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2025-07-29
CVE-2025-43229 at NVD
1 known exploit for CVE-2025-43229
Proof-of-concept code and exploit modules indexed by Sploitus