CVE-2025-43392 | Apple Safari/tvOS/visionOS/watchOS/iOS/iPadOS up to 26.0 cross-domain policy (Nessus ID 276572 / WID-SEC-2025-2480)
A vulnerability classified as problematic has been found in Apple Safari, tvOS, visionOS, watchOS, iOS and iPadOS up to 26.0. This issue affects some unknown processing. Performing manipulation results in permissive cross-domain policy with untrusted domains.
This vulnerability is identified as CVE-2025-43392. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.