Impact
A malicious website can craft content that bypasses the web view sandbox, enabling a webkitgtk process to handle resources that are normally restricted. This represents an Improper Access Control flaw (CWE‑284). The impact is that data or code stored within sandboxed content can be exposed or executed by an attacker, potentially enabling further compromise of the device. The vulnerability was addressed with improved checks in Apple’s releases 26.5.2 (Safari, iOS, iPadOS, macOS) and 26.6 (tvOS, visionOS, watchOS).
Affected Systems
Affected are Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Versions older than Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6 are vulnerable. The fixes are applied in those releases and later.
Risk and Exploitability
The flaw can be triggered by a user visiting a specially crafted web page; no additional privileges are required. Because the attack allows sandbox escape, it can affect the entire device. The EPSS score is less than 1%, the vulnerability is not listed in KEV, and the CVSS score of 7.1 indicates high severity. Attack likely proceeds over standard web traffic, such as HTTPS or HTTP, from an untrusted site.
OpenCVE Enrichment
Debian DSA