Impact
A malicious website can serve content that bypasses the WebKitGTK sandbox, allowing untrusted code or data to be processed by a privileged web-kit process. This Improper Access Control flaw (CWE‑284) enables a sandbox escape, potentially leaking sandboxed resources or executing code outside the intended isolation. The patching of this issue is available in Safari 26.5.2, iOS 18.7.10, iPadOS 18.7.10, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. Until those updates are applied, the vulnerability remains exploitable.
Affected Systems
Affected are Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Versions older than Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6 are vulnerable. The fixes are applied in those releases and later.
Risk and Exploitability
The flaw can be triggered by a user visiting a specially crafted web page; no additional privileges are required. Because the attack allows sandbox escape, it can affect the entire device. The EPSS score is less than 1%, the vulnerability is not listed in KEV, and the CVSS score of 7.1 indicates high severity. Attack likely proceeds over standard web traffic, such as HTTPS or HTTP, from an untrusted site.
OpenCVE Enrichment
Debian DSA