CVE-2025-43240
A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. A download's origin may be incorrectly associated.
- Affected products
- Almalinux, Astra Linux, Centos, Debian, Linuxmint, Apple Macos, Red Hat, Rocky Linux
- Apple Safari
- < 18.6
- Apple Macos
- < 15.6
- CVSS 3.1
- 6.2 MEDIUM
- EPSS
- 0.9% (57th percentile)
- Weakness
- CWE-703
- NVD status
- Modified
- Published
- 2025-07-29
CVE-2025-43240 at NVD
1 known exploit for CVE-2025-43240
Proof-of-concept code and exploit modules indexed by Sploitus