This issue was addressed with improved URL validation. This issue is fixed in macOS Tahoe 26.2, Safari 26.2. On a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted.
[ { "events": [ { "introduced": "0" }, { "fixed": "26.2" } ] }, { "events": [ { "introduced": "0" }, { "fixed": "26.2" } ] } ]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-43526.json"