Impact
This vulnerability is a state management flaw that permits a malicious website to circumvent the browser’s Same Origin Policy, potentially allowing unauthorized access to cross‑origin resources. The flaw could lead to exfiltration of sensitive data or the execution of scripts in the context of another origin, thereby compromising confidentiality and integrity. The CVSS score of 9.8 indicates a very high severity rating.
Affected Systems
The flaw affects Apple Safari, iOS, iPadOS, macOS, and visionOS. Versions older than 18.4 for Safari, iOS and iPadOS, 15.4 for macOS, and 2.4 for visionOS remain vulnerable. Devices running these operating systems without the specified updates are at risk.
Risk and Exploitability
The EPSS score of less than 1% suggests that exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalog. It is reasonably inferred that a typical attack would involve a user visiting a malicious website, which could exploit the state‑management flaw to violate the Same Origin Policy. Given the high CVSS score and the potential for cross‑origin manipulation, security professionals should treat this as a critical issue pending the latest updates.
OpenCVE Enrichment
EUVD