CVE-2025-43240: Apple macOS

Medium severity, CVSS 6.2. EPSS: 1% chance of exploitation in the next 30 days.

A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. A download's origin may be incorrectly associated.

Affected products

  • Apple macOS: before 15.6 (fixed in 15.6)
  • Apple Safari: before 18.6 (fixed in 18.6)

Published 2025-07-30. Last modified 2026-06-17.