Impact
A logging flaw allowed an application to read a user’s Safari browsing history due to incomplete data redaction. The defect is classified as Logging of Sensitive Information (CWE-532). The impact is the exposure of personal browsing activity, compromising user privacy. No broader integrity or availability effects are reported.
Affected Systems
Apple iOS 26.2, iPadOS 26.2, macOS Tahoe 26.2, and watchOS 26.2 are affected. Devices running any earlier version are vulnerable.
Risk and Exploitability
The CVSS score of 5.5 places the vulnerability in the moderate range, while the EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack requires a local application with user‑level permissions to read the compromised logs, so the exposure is limited to the privacy of the device’s current user.
OpenCVE Enrichment