Impact
A caching mishandling flaw in the WebKitGTK engine can allow a malicious website to read sensor information such as device orientation or motion data without obtaining explicit user permission, thereby leaking private data that could be used for tracking or spying.
Affected Systems
The vulnerability affects Apple browsers that use Safari's WebKitGTK rendering engine, including Safari on macOS, iOS, iPadOS, tvOS, visionOS, and watchOS. The flaw is patched in Safari 26, iOS 18.7 and 26, iPadOS 18.7 and 26, macOS Tahoe 26, tvOS 26, visionOS 26, and watchOS 26, so any device or OS version preceding these releases is susceptible.
Risk and Exploitability
The issue carries a CVSS score of 6.5, indicating moderate severity, and a very low EPSS score of less than 1%, suggesting few exploitation attempts are expected. Because the flaw can be triggered through arbitrary web content loaded in Safari, the attack vector is likely a web-based attack that does not require privileged access. The vulnerability is not listed in CISA's KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA
EUVD
Ubuntu USN