Information Exposure in Safari and Apple Operating Systems
CVE-2025-31192
6.7MEDIUM
Summary
An information exposure vulnerability was identified in Safari and several Apple operating systems, allowing unauthorized websites to access sensitive sensor data without user authorization. This security risk was mitigated in the latest updates, which provide enhanced checks to prevent this unsolicited access to personal data.
Affected Version(s)
iOS and iPadOS < 18.4
macOS < 15.4
Safari < 18.4
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved