Impact
A malicious website may process restricted web content outside the browser sandbox, allowing an attacker to access or execute content that should be confined, effectively bypassing the intended access controls. This type of weakness falls under improper access control and can lead to data leakage or execution of unintended code within the operating system environment.
Affected Systems
Affected are Apple Safari, iOS, iPadOS, and macOS. Versions prior to Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2 are vulnerable. The fixes are deployed in those 26.5.2 releases and later.
Risk and Exploitability
The exploitation can be achieved by a user visiting a crafted web page; it does not require privileged access or additional configuration. Because the flaw permits sandbox escape, the impact can be broad, potentially affecting the entire device. The EPSS score is not available and the vulnerability is not listed in the KEV catalog, yet the nature of a sandbox escape warrants high caution. The likely attack vector is remote via an untrusted website over standard web traffic.
OpenCVE Enrichment