CVE-2025-43480 | Apple Safari/tvOS/visionOS/watchOS/iOS/iPadOS up to 26.0 Website cross-domain policy
A vulnerability was found in Apple Safari, tvOS, visionOS, watchOS, iOS and iPadOS up to 26.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Website Handler. Executing manipulation can lead to permissive cross-domain policy with untrusted domains.
This vulnerability is registered as CVE-2025-43480. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.