CVE-2025-30425
MEDIUM | Platform: iPadOS | Changelog
CVE Details
Description
This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. A malicious website may be able to track users in Safari private browsing mode.
CVSS 3.1 Score
| Metric | Value |
|---|---|
| Base Score | 4.3 (MEDIUM) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
Weakness
References
- Apple Security Advisory
- NVD Entry
- https://support.apple.com/en-us/122371 (Vendor Advisory)
- https://support.apple.com/en-us/122373 (Vendor Advisory)
- https://support.apple.com/en-us/122376
- https://support.apple.com/en-us/122377 (Vendor Advisory)
- https://support.apple.com/en-us/122379 (Vendor Advisory)
- http://seclists.org/fulldisclosure/2025/Apr/11
- http://seclists.org/fulldisclosure/2025/Apr/13