Impact
A permissions flaw in the Apple web browser stack allows a malicious web page to read private data from the browsing environment when a user visits the site. The flaw permits access to cookies, credentials, or other locally stored information that should be protected by the browser’s permission model, and is catalogued as CWE‑284. The typical impact is sensitive user data disclosure, compromising privacy rather than causing direct code execution.
Affected Systems
Apple Safari, iOS, iPadOS, and macOS Tahoe running versions earlier than 26.5.2 are affected. The vulnerability is resolved in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2, where the excessive permission is revoked.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity, and the EPSS score of < 1% reflects a very low known exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attack is likely via a malicious or compromised website that a user visits; the attacker needs no special privileges beyond loading a URL. No exploit evidence is reported, suggesting the risk is largely theoretical, but the potential for data exposure warrants prompt patching.
OpenCVE Enrichment