Description
A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be able to spoof the domain name in the title of a pop-up window.
Published: 2025-11-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Domain Spoofing in Pop‑Up Window Title
Action: Update Safari
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 23:15:00 +0000

Type Values Removed Values Added
Title Spoofing of Domain Name in Safari Pop-Up Window Title

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be able to spoof the domain name in the title of a pop-up window. A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be able to spoof the domain name in the title of a pop-up window.

Wed, 26 Nov 2025 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Apple safari
Vendors & Products Apple
Apple macos
Apple safari

Sun, 23 Nov 2025 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Nov 2025 21:30:00 +0000

Type Values Removed Values Added
Description A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be able to spoof the domain name in the title of a pop-up window.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:19:21.476Z

Reserved: 2025-03-27T16:13:58.340Z

Link: CVE-2025-31266

cve-icon Vulnrichment

Updated: 2025-11-23T11:31:41.656Z

cve-icon NVD

Status : Modified

Published: 2025-11-21T22:16:19.743

Modified: 2026-04-02T19:19:58.183

Link: CVE-2025-31266

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-27T23:00:13Z

Weaknesses