Impact
A vulnerability in Apple’s WebKitGTK component allows a locally‑running application to read sensitive user data it should not access, due to insufficient data protection mechanisms. The flaw was addressed by applying improved data protection techniques, and the fix is incorporated in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, and visionOS 26.5. Until these updates are installed, an app may be able to access confidential information stored on the device.
Affected Systems
Apple systems that had not yet installed version 26.5 of iOS, iPadOS, macOS (Tahoe), or visionOS are vulnerable. The issue is corrected in iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, and visionOS 26.5, so all earlier releases remain susceptible.
Risk and Exploitability
The exploitability details are not quantified; EPSS score is < 1% and the vulnerability is not listed in CISA KEV. The flaw allows a malicious or compromised application to read protected user data, indicating a moderate risk for confidentiality loss. The CVSS score of 5.5 confirms the vulnerability is of moderate severity. The attack vector is inferred to be local or via inter‑app cooperation depending on sandbox boundaries, with no indication that remote exploitation is required.
OpenCVE Enrichment
Debian DSA