Impact
The vulnerability is a cross‑origin issue where the browser’s tracking of security origins was insufficient, allowing maliciously crafted web content to disclose sensitive user information. This weakness aligns with CWE-346.
Affected Systems
Affected systems are Apple’s web browser and platform components: Safari, iOS, iPadOS, and macOS Tahoe. The issue is fixed in version 26.5.2 for Safari, iOS, iPadOS, and macOS Tahoe; users running earlier releases are potentially exposed.
Risk and Exploitability
A CVSS score of 6.5 indicates medium severity and no EPSS score or KEV listing suggests that exploitation has not yet been observed or reported in the wild. Based on the description, it is inferred that attackers could entice users to visit malicious websites or fall for social engineering or drive‑by phishing attacks to exploit this cross‑origin information leakage. While no public exploits exist, the potential for sensitive data disclosure warrants prompt patching.
OpenCVE Enrichment