Impact
The vulnerability is a cross-origin issue arising from insufficient tracking of security origins. An attacker can craft malicious web content that triggers the browser to disclose sensitive user information across origins, which aligns with CWE‑346.
Affected Systems
Affected systems are Apple’s web browser and platform components: Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS. The issue is fixed in version 26.5.2 for Safari, iOS, iPadOS, and macOS Tahoe, and in version 26.6 for tvOS, visionOS, and watchOS; users running earlier releases are potentially exposed.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score of <1% shows that exploitation is expected to be very low, and the vulnerability is not listed in CISA’s KEV catalog. Therefore, no widespread exploitation has been observed. The weakness, rooted in improper origin tracking (CWE‑346), could allow an attacker to cause the browser to reveal private data from a web page that belongs to a different origin, potentially bypassing same-origin policies.
OpenCVE Enrichment