CVE-2025-31266: Double Free
A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be able to spoof the domain name in the title of a pop-up window.
Other sources
afpfs. The issue was addressed with improved memory handling.
— Apple
afpfs. This issue was addressed with improved checks.
— Apple
Apple Intelligence Reports. A permissions issue was addressed with additional restrictions.
— Apple
AppleJPEG. The issue was addressed with improved input sanitization.
— Apple
Audio. A double free issue was addressed with improved memory management.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-31266
- CVE-2025-24213
- CVE-2025-31223
- CVE-2025-31238
- CVE-2025-24223
- CVE-2025-31204
- CVE-2025-31217
- CVE-2025-31215
- CVE-2025-31206
- CVE-2025-31205
- CVE-2025-31257
- CVE-2025-31246
- CVE-2025-31240
- CVE-2025-31237
- CVE-2025-31260
- CVE-2025-31251
- CVE-2025-31235
- CVE-2025-24222
- CVE-2025-31212
- CVE-2025-31208
- CVE-2025-31209
- CVE-2025-31239
- CVE-2025-31233
- CVE-2025-31236
- CVE-2025-30443
- CVE-2025-31226
- CVE-2025-31232
- CVE-2025-24224
- CVE-2025-31241
- CVE-2025-31219
- CVE-2024-8176
- CVE-2025-30440
- CVE-2025-31222
- CVE-2025-24274
- CVE-2025-31218
- CVE-2025-31256
- CVE-2025-24142
- CVE-2025-26465
- CVE-2025-26466
- CVE-2025-31234
- CVE-2025-31245
- CVE-2025-31244
- CVE-2025-31258
- CVE-2025-31249
- CVE-2025-31224
- CVE-2025-31221
- CVE-2025-31213
- CVE-2025-31247
- CVE-2025-31259
- CVE-2025-31242
- CVE-2025-31250
- CVE-2025-31248
- CVE-2025-31220
- CVE-2025-43374
Frequently Asked Questions
What is the severity of CVE-2025-31266?
CVE-2025-31266 has a moderate severity level due to its potential for spoofing domain names in pop-up windows.
How do I fix CVE-2025-31266?
To mitigate CVE-2025-31266, update to Safari version 18.5 or macOS Sequoia version 15.5 or later.
What types of systems are affected by CVE-2025-31266?
CVE-2025-31266 affects Apple Safari prior to version 18.5 and macOS Sequoia prior to version 15.5.
What kind of attack does CVE-2025-31266 enable?
CVE-2025-31266 enables attackers to spoof domain names in the titles of pop-up windows, potentially misleading users.
When was CVE-2025-31266 addressed?
CVE-2025-31266 was addressed in the updates released for Safari 18.5 and macOS Sequoia 15.5.