Description
This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. A website may be able to bypass Same Origin Policy.
Published: 2025-05-29
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Same Origin Policy Bypass
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a state management flaw that permits a malicious website to circumvent the browser’s Same Origin Policy, potentially allowing unauthorized access to cross‑origin resources. The flaw could lead to exfiltration of sensitive data or the execution of scripts in the context of another origin, thereby compromising confidentiality and integrity. The CVSS score of 9.8 indicates a very high severity rating.

Affected Systems

The flaw affects Apple Safari, iOS, iPadOS, macOS, and visionOS. Versions older than 18.4 for Safari, iOS and iPadOS, 15.4 for macOS, and 2.4 for visionOS remain vulnerable. Devices running these operating systems without the specified updates are at risk.

Risk and Exploitability

The EPSS score of less than 1% suggests that exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalog. It is reasonably inferred that a typical attack would involve a user visiting a malicious website, which could exploit the state‑management flaw to violate the Same Origin Policy. Given the high CVSS score and the potential for cross‑origin manipulation, security professionals should treat this as a critical issue pending the latest updates.

Generated by OpenCVE AI on April 28, 2026 at 11:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest updates for Safari, iOS, iPadOS, macOS, and visionOS (18.4 / 15.4 / 2.4).
  • Ensure all devices receiving these operating systems are configured for automatic updates or arrange manual installation to deploy the patches promptly.
  • As an interim defensive measure, consider restricting cross‑origin requests by configuring browser security settings or employing site‑specific content‑security policies until the official patch is deployed.

Generated by OpenCVE AI on April 28, 2026 at 11:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-16423 This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, visionOS 2.4, macOS Sequoia 15.4. A website may be able to bypass Same Origin Policy.
History

Tue, 28 Apr 2026 11:30:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via State Management Flaw

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, visionOS 2.4, macOS Sequoia 15.4. A website may be able to bypass Same Origin Policy. This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. A website may be able to bypass Same Origin Policy.

Mon, 02 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ipados
Apple iphone Os
Apple macos
Apple safari
Apple visionos
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple ipados
Apple iphone Os
Apple macos
Apple safari
Apple visionos

Fri, 30 May 2025 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 29 May 2025 21:45:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, visionOS 2.4, macOS Sequoia 15.4. A website may be able to bypass Same Origin Policy.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:27:10.218Z

Reserved: 2025-03-22T00:04:43.722Z

Link: CVE-2025-30466

cve-icon Vulnrichment

Updated: 2025-05-30T14:42:06.620Z

cve-icon NVD

Status : Modified

Published: 2025-05-29T22:15:21.603

Modified: 2026-04-02T19:19:41.870

Link: CVE-2025-30466

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T11:15:26Z

Weaknesses