This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content may lead to unexpected URL redirection.
Metrics
Affected Vendors & Products
References
History
Wed, 17 Sep 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apple ipados
Apple iphone Os |
|
CPEs | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Apple ipados
Apple iphone Os |
Wed, 17 Sep 2025 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apple
Apple ios Apple ipad Os Apple safari |
|
Vendors & Products |
Apple
Apple ios Apple ipad Os Apple safari |
Tue, 16 Sep 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-863 | |
Metrics |
cvssV3_1
|
Mon, 15 Sep 2025 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content may lead to unexpected URL redirection. | |
References |
|

Status: PUBLISHED
Assigner: apple
Published: 2025-09-15T22:34:24.377Z
Updated: 2025-09-16T15:15:26.286Z
Reserved: 2025-03-27T16:13:58.336Z
Link: CVE-2025-31254

Updated: 2025-09-16T15:10:45.797Z

Status : Analyzed
Published: 2025-09-15T23:15:29.703
Modified: 2025-09-17T13:34:44.453
Link: CVE-2025-31254

No data.