This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content may lead to unexpected URL redirection.
Metrics
Affected Vendors & Products
References
History
Wed, 17 Sep 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple ipados
Apple iphone Os |
|
| CPEs | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apple ipados
Apple iphone Os |
Wed, 17 Sep 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple ios Apple ipad Os Apple safari |
|
| Vendors & Products |
Apple
Apple ios Apple ipad Os Apple safari |
Tue, 16 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 | |
| Metrics |
cvssV3_1
|
Mon, 15 Sep 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content may lead to unexpected URL redirection. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published: 2025-09-15T22:34:24.377Z
Updated: 2025-09-16T15:15:26.286Z
Reserved: 2025-03-27T16:13:58.336Z
Link: CVE-2025-31254
Updated: 2025-09-16T15:10:45.797Z
Status : Analyzed
Published: 2025-09-15T23:15:29.703
Modified: 2025-09-17T13:34:44.453
Link: CVE-2025-31254
No data.