
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43526 is a URL validation vulnerability in Apple Safari and macOS Tahoe that allows web content opened via a file URL to bypass Web API restrictions on systems with Lockdown Mode enabled. It was discovered by Andreas Jaegersberger and Ro Achterberg of Nosebeard Labs and disclosed on December 12, 2025, when Apple released patches. The vulnerability affects Safari and macOS versions prior to 26.2. It carries a CVSS v3.1 base score of 9.8 (Critical), as assessed by CISA-ADP (Apple macOS Advisory, Apple Safari Advisory).
The root cause is insufficient URL validation (CWE-601: URL Redirection to Untrusted Site / Open Redirect) in Safari's handling of file URLs. When web content is loaded via a file:// URL on a Mac with Lockdown Mode enabled, the browser fails to properly enforce the Web API restrictions that Lockdown Mode is designed to impose, allowing the content to access APIs that should be blocked. Lockdown Mode is Apple's enhanced security feature intended to protect high-risk users (e.g., journalists, activists) from sophisticated targeted attacks, making this bypass particularly significant. No public proof-of-concept or detailed technical write-up has been published as of the time of this report (Apple macOS Advisory, Apple Safari Advisory).
Successful exploitation allows web content delivered via a file URL to access restricted Web APIs on Macs running Lockdown Mode, directly undermining the enhanced security protections that mode provides. This could result in high confidentiality, integrity, and availability impacts, as the CISA-ADP CVSS assessment reflects. The vulnerability is particularly concerning for high-risk individuals who rely on Lockdown Mode as a defense against sophisticated, targeted attacks, as it nullifies a key layer of their security posture (Apple macOS Advisory, Apple Safari Advisory).
file:// URL in Safari.file:// URL contexts on systems with Lockdown Mode enabled.Apple has released patches addressing this vulnerability in Safari 26.2 and macOS Tahoe 26.2, both released on December 12, 2025. Users should update to these versions or later immediately, with priority given to systems that have Lockdown Mode enabled, as those are the directly affected configurations. As a temporary workaround for systems that cannot be immediately patched, administrators may consider disabling file URL access in Safari or avoiding opening untrusted local HTML files until the patch is applied (Apple macOS Advisory, Apple Safari Advisory).
The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Apple products that could allow for arbitrary code execution, which included CVE-2025-43526 in its scope. The vulnerability was also noted by SANS Internet Storm Center shortly after disclosure. Community attention has been moderate, with the vulnerability appearing in standard security aggregation feeds and vulnerability databases, but no major independent researcher commentary or media coverage specific to this CVE has been identified beyond routine patch reporting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."