CVE Vulnerabilities

CVE-2025-43493

Authentication Bypass by Spoofing

Published: Nov 04, 2025 | Modified: Dec 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.1, iOS 26.1 and iPadOS 26.1, Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, visionOS 26.1. Visiting a malicious website may lead to address bar spoofing.

Weakness

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Affected Software

NameVendorStart VersionEnd Version
SafariApple*26.1 (excluding)
IpadosApple*26.1 (excluding)
Iphone_osApple*26.1 (excluding)
VisionosApple*26.1 (excluding)

References