Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY281 SECURITY RECORDS

Apple

Safari

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

Official registry publication history is available at safari, but registry activity is not a publisher support boundary.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-20644 11 Feb 2026 < 26.3; < 18.7.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-20652 11 Feb 2026 < 26.3; < 18.7.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-20608 11 Feb 2026 < 26.3; < 18.7.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-20635 11 Feb 2026 < 26.3; < 18.7.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-20660 11 Feb 2026 < 26.3; < 18.7.5; < 14.8.4; < 15.7.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-20676 11 Feb 2026 < 26.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-20656 11 Feb 2026 < 26.3; < 18.7.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-20636 11 Feb 2026 < 26.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-46298 9 Jan 2026 < 26.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-46299 9 Jan 2026 < 26.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43535 17 Dec 2025 Safari: < 26.2; iOS and iPadOS: < 18.7.3, < 26.2; macOS: < 26.2; visionOS: < 26.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43526 17 Dec 2025 < 26.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43531 17 Dec 2025 Safari: < 26.2; iOS and iPadOS: < 18.7.3, < 26.2; macOS: < 26.2; tvOS: < 26.2; visionOS: < 26.2; watchOS: < 26.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43536 17 Dec 2025 < 26.2; < 18.7.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43541 17 Dec 2025 Safari: < 26.2; iOS and iPadOS: < 18.7.3, < 26.2; macOS: < 26.2; visionOS: < 26.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43501 17 Dec 2025 Safari: < 26.2; iOS and iPadOS: < 18.7.3, < 26.2; macOS: < 26.2; visionOS: < 26.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-46282 17 Dec 2025 < 26.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43511 12 Dec 2025 Safari: < 26.2; iOS and iPadOS: < 18.7.2, < 26.2; macOS: < 26.2; visionOS: < 26.2; watchOS: < 26.2 RHSA-2026:22136: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS) Update reference ↗
CVE-2025-31266 21 Nov 2025 < 18.5; < 15.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43430 4 Nov 2025 < 26.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43502 4 Nov 2025 < 26.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43493 4 Nov 2025 Safari: < 26.1; iOS and iPadOS: < 18.7.2, < 26.1; macOS: < 26.1; visionOS: < 26.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43503 4 Nov 2025 Safari: < 26.1; iOS and iPadOS: < 18.7.2, < 26.1; macOS: < 26.1; visionOS: < 26.1; watchOS: < 26.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43427 4 Nov 2025 < 26.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43431 4 Nov 2025 < 26.1; < 18.7.2 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2025-43457 4 Nov 2025 < 26.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43441 4 Nov 2025 < 26.1; < 18.7.2 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2025-43421 4 Nov 2025 < 26.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43440 4 Nov 2025 < 26.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43438 4 Nov 2025 Safari: < 26.1; iOS and iPadOS: < 18.7.2, < 26.1; macOS: < 26.1; visionOS: < 26.1; watchOS: < 26.1 RHSA-2025:22789: Red Hat Enterprise Linux AppStream (v. 8) Update reference ↗
CVE-2025-43480 4 Nov 2025 < 26.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43443 4 Nov 2025 Safari: < 26.1; iOS and iPadOS: < 18.7.2, < 26.1; macOS: < 26.1; tvOS: < 26.1; visionOS: < 26.1; watchOS: < 26.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43434 4 Nov 2025 Safari: < 26.1; iOS and iPadOS: < 18.7.2, < 26.1; macOS: < 26.1; visionOS: < 26.1; watchOS: < 26.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43376 4 Nov 2025 < 26; < 18.7.7 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43458 4 Nov 2025 Safari: < 26.1; iOS and iPadOS: < 18.7.2, < 26.1; macOS: < 26.1; tvOS: < 26.1; visionOS: < 26.1; watchOS: < 26.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43419 4 Nov 2025 < 26 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2025-43435 4 Nov 2025 < 26.1; < 18.7.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43432 4 Nov 2025 < 26.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43392 4 Nov 2025 < 26.1; < 18.7.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43429 4 Nov 2025 Safari: < 26.1; iOS and iPadOS: < 18.7.2, < 26.1; macOS: < 26.1; tvOS: < 26.1; visionOS: < 26.1; watchOS: < 26.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43433 4 Nov 2025 Safari: < 26.1; iOS and iPadOS: < 18.7.2, < 26.1; macOS: < 26.1; tvOS: < 26.1; visionOS: < 26.1; watchOS: < 26.1 RHSA-2025:22789: Red Hat Enterprise Linux AppStream (v. 8) Update reference ↗
CVE-2025-43425 4 Nov 2025 < 26.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43368 15 Sep 2025 < 26 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2025-43343 15 Sep 2025 < 26 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43342 15 Sep 2025 < 26; < 18.7 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43272 15 Sep 2025 < 26 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43356 15 Sep 2025 < 26; < 18.7 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-31254 15 Sep 2025 < 26 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43327 15 Sep 2025 < 26 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-43265 29 Jul 2025 < 18.6; < 15.6; < 2.6; < 11.6 No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.