CVE-2025-43229
Description
This issue was addressed through improved state management. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to universal cross site scripting.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2025-43229 is a universal XSS vulnerability in WebKit addressed in Safari 18.6 and macOS Sequoia 15.6, allowing attackers to execute cross-site scripting via malicious web content.
Root
Cause
CVE-2025-43229 is a vulnerability in the WebKit rendering engine that could lead to universal cross-site scripting (UXSS). The issue, discovered by Martin Bajanik of Fingerprint and Ammar Askar, was addressed through improved state management in WebKit [1][4]. This type of flaw occurs when the browser incorrectly handles security contexts, allowing scripts from one origin to execute in the context of another.
Exploitation
The attack vector requires processing maliciously crafted web content, such as a specially designed webpage. No additional user interaction beyond visiting the malicious page is necessary for exploitation. The vulnerability is present in Safari on both macOS and iOS, as well as any application using WebKit on these platforms [4].
Impact
Successful exploitation can lead to universal cross-site scripting, enabling an attacker to inject arbitrary scripts into the user's browser session. This may allow stealing cookies, session tokens, or performing actions on behalf of the user across different websites, bypassing standard same-origin policy protections.
Mitigation
Apple has released fixes in Safari 18.6, available for macOS Ventura and macOS Sonoma, and in macOS Sequoia 15.6 [1][3]. Users should update their devices to the latest versions to protect against this vulnerability.
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*range: <18.6
- (no CPE)range: <18.6
- Range: <15.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- support.apple.com/en-us/124149nvdRelease NotesVendor Advisory
- support.apple.com/en-us/124152nvdRelease NotesVendor Advisory
- seclists.org/fulldisclosure/2025/Aug/0nvd
- seclists.org/fulldisclosure/2025/Jul/32nvd
News mentions
0No linked articles in our index yet.