CVE-2025-31266: Apple macOS

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be able to spoof the domain name in the title of a pop-up window.

Affected products

  • Apple macOS: before 15.5 (fixed in 15.5)
  • Apple Safari: before 18.5 (fixed in 18.5)

Published 2025-11-21. Last modified 2026-06-17.