Impact
A logic flaw in Apple’s WebKit engine allows a malicious website to read or interact with script message handlers that belong to other origins. The vulnerability is a cross‑origin data access issue identified as CWE-346, which can expose internal communication mechanisms and potentially allow an attacker to execute unintended code paths or exfiltrate sensitive information.
Affected Systems
The flaw affects Apple’s browsers and operating systems, including Safari on macOS and visionOS, as well as web views embedded in iOS and iPadOS applications. It is fixed in Safari 26.4, iOS and iPadOS 18.7.7/26.4, macOS Tahoe 26.4 and visionOS 26.4. Versions prior to these releases are potentially vulnerable.
Risk and Exploitability
The CVSS score of 4.3 denotes moderate impact, the EPSS score indicates a very low probability of exploitation (under 1%), and the vulnerability is not listed in CISA’s KEV catalog. Attacks would be performed by a user visiting a compromised site, making exploitation a remote, client‑side event. While the risk is limited, the impact to confidentiality of inter‑origin communication warrants timely remediation.
OpenCVE Enrichment