4.3

CVE-2025-30425

This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. A malicious website may be able to track users in Safari private browsing mode.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ Safari Version < 18.4
Apple ≫ iPadOS Version < 17.7.6
Apple ≫ iPadOS Version >= 18.0 < 18.4
Apple ≫ iPhone OS Version < 18.4
Apple ≫ macOS Version >= 15.0 < 15.4
Apple ≫ tvOS Version < 18.4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.75% 0.516
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://support.apple.com/en-us/122371
Vendor Advisory
https://support.apple.com/en-us/122373
Vendor Advisory
https://support.apple.com/en-us/122377
Vendor Advisory
https://support.apple.com/en-us/122379
Vendor Advisory
https://support.apple.com/en-us/122372
Vendor Advisory
https://support.apple.com/en-us/122376
http://seclists.org/fulldisclosure/2025/Apr/13
http://seclists.org/fulldisclosure/2025/Apr/8
http://seclists.org/fulldisclosure/2025/Apr/11
http://seclists.org/fulldisclosure/2025/Apr/4
http://seclists.org/fulldisclosure/2025/Apr/5
http://seclists.org/fulldisclosure/2025/Apr/2