The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. A malicious website may exfiltrate data cross-origin.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-31205.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "18.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "18.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "18.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "15.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "18.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "11.5"
}
]
}
]