Impact
The vulnerability is a logic issue that allows a malicious website to execute arbitrary scripting code within the browsing context. Because the flaw was not properly checked, a site can cause the browser to run any JavaScript entered by the attacker. This results in a classic cross‑site scripting attack that can compromise user data, session credentials, or execute further malicious payloads. The weakness is classified as CWE‑79.
Affected Systems
Affected products are Apple Safari on macOS, iOS, and iPadOS. The flaw is present in Safari versions prior to 26.4, iOS and iPadOS prior to 18.7.7 (and 26.4), and macOS Tahoe prior to 26.4. Users running any earlier builds are potentially vulnerable.
Risk and Exploitability
The CVSS base score is 4.3, indicating low‑to‑moderate severity, and the EPSS score is less than 1 %, suggesting a low probability of exploitation in the wild. Apple has not listed this vulnerability in the KEV catalog. The attack likely requires a user to visit a crafted site, so the vector is remote web-based. The overall risk is modest, but any reachable data could be exposed if the site is visited.
OpenCVE Enrichment