Description
A logic issue was addressed with improved state management. This issue is fixed in Safari 26, iOS 18.7.7 and iPadOS 18.7.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. A remote attacker may be able to view leaked DNS queries with Private Relay turned on.
Published: 2025-11-04
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure via leaked DNS queries when Private Relay is enabled
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises from a logic flaw in state management that allows a remote attacker to view DNS queries embedded in traffic when Private Relay is turned on. The flaw enables exposure of the DNS queries an end‑user issued, thereby leaking location or request details that should be confidential. The official description states that the logic issue was addressed with improved state management and that the bug is fixed in later releases of Safari and several Apple operating systems.

Affected Systems

Apple Safari, iOS 18.7.7 and 26, iPadOS 18.7.7 and 26, macOS Tahoe 26, tvOS 26, visionOS 26, and watchOS 26 are affected. These versions have been patched to prevent the leakage of DNS queries via Private Relay.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity but the EPSS score of < 1% suggests that exploitation in the wild is unlikely as of this analysis. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, requiring the victim to use Private Relay and a malicious resource that triggers the logic flaw; many of the steps to exploit it are unspecified, so the exact method is inferred rather than explicitly documented.

Generated by OpenCVE AI on April 27, 2026 at 23:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Safari 26 and to the corresponding iOS, iPadOS, macOS, tvOS, visionOS, or watchOS version that incorporates the fix (iOS 18.7.7 or 26, iPadOS 18.7.7 or 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26).
  • If a patch update cannot be applied immediately, disable Private Relay on affected devices until the fix is installed to remove the trigger for the logic flaw.
  • Monitor network traffic for anomalous DNS query patterns that might indicate exploitation attempts and review device logs for unexpected query exposure.

Generated by OpenCVE AI on April 27, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Title Leakage of DNS Queries via Private Relay in Apple Safari and Operating Systems
Weaknesses CWE-200

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved state management. This issue is fixed in Safari 26, tvOS 26, watchOS 26, iOS 26 and iPadOS 26, visionOS 26. A remote attacker may be able to view leaked DNS queries with Private Relay turned on. A logic issue was addressed with improved state management. This issue is fixed in Safari 26, iOS 18.7.7 and iPadOS 18.7.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. A remote attacker may be able to view leaked DNS queries with Private Relay turned on.
References

Wed, 10 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Nov 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple iphone Os
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple iphone Os
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Tue, 04 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios
Apple ipados
Apple safari
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios
Apple ipados
Apple safari
Apple tvos
Apple visionos
Apple watchos

Tue, 04 Nov 2025 01:45:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved state management. This issue is fixed in Safari 26, tvOS 26, watchOS 26, iOS 26 and iPadOS 26, visionOS 26. A remote attacker may be able to view leaked DNS queries with Private Relay turned on.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:14:59.217Z

Reserved: 2025-04-16T15:24:37.115Z

Link: CVE-2025-43376

cve-icon Vulnrichment

Updated: 2025-12-10T20:46:08.520Z

cve-icon NVD

Status : Modified

Published: 2025-11-04T02:15:44.710

Modified: 2026-04-02T19:20:35.927

Link: CVE-2025-43376

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-27T23:30:15Z

Weaknesses