Impact
An inconsistency in state management within the user interface can be exploited by visiting a malicious website, resulting in UI spoofing. The vulnerability is catalogued as CWE-290.
Affected Systems
Apple Safari, Apple iOS, Apple iPadOS, Apple macOS, Apple visionOS, and Apple watchOS are impacted. Versions affected include Safari 26.1, iOS 18.7.2 and 26.1, iPadOS 18.7.2 and 26.1, macOS Tahoe 26.1, visionOS 26.1, and watchOS 26.1.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate potential for exploitation, while an EPSS score of less than 1% shows extremely low current community interest in exploiting this flaw. The vulnerability is not listed in the CISA KEV catalog. The probable attack vector is a malicious website that induces the user to interact with spoofed UI elements, thereby tricking users into unintended actions. No additional prerequisites beyond visiting such a site are required.
OpenCVE Enrichment