Impact
A vulnerability in Apple web browsers allows a malicious website to exfiltrate data across origins by exploiting insufficient input validation. The flaw can compromise the confidentiality of any data a user has stored in the browser or associated with that origin, as the attacker can request and transmit the data to a domain they control. This is essentially an input validation failure that enables a classical data‑leakage attack.
Affected Systems
Apple Safari, iOS, iPadOS and macOS Tahoe run the vulnerability before the release of Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2 and macOS Tahoe 26.5.2. Versions older than 26.5.2 are affected, and the issue is fixed in the 26.5.2 releases for each platform.
Risk and Exploitability
Based on the description, it is inferred that a malicious website could trigger the flaw by loading a page in the affected browser; the CVE data does not explicitly state the requisite privileges or network exploitation prerequisites. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of these metrics does not diminish its potential severity. The CVSS score of 4.3 indicates a medium level of severity for this client‑side data‑exfiltration flaw.
OpenCVE Enrichment