Description
A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Visiting a website may leak sensitive data.
Published: 2026-06-29
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A permissions flaw in the Apple web browser stack allows a malicious web page to access and leak sensitive data. This occurs when a site is visited, giving the browser more privileges than intended and enabling disclosure of private information such as cookies, credentials, or other local data. The weakness is a classic permissions problem and could compromise user privacy if exploited.

Affected Systems

Apple Safari, iOS, iPadOS, and macOS on the Tahoe platform are affected. The flaw is resolved in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2, each of which removes the excessive access that permits data leakage.

Risk and Exploitability

Exploit evidence is not reported; EPSS is not available and the vulnerability is not listed in CISA’s KEV catalog. The risk remains that an attacker can craft a malicious web page that, when loaded in the affected browsers, reads sensitive data and transmits it out. The attack requires no special privileges beyond visiting a URL, making it potentially scalable for distributed web-based attacks. The absence of exploit data suggests limited current exploitation, but the intrinsic possibility of data exposure warrants prompt patching.

Generated by OpenCVE AI on June 29, 2026 at 21:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Safari update to version 26.5.2
  • Apply iOS and iPadOS update to version 26.5.2
  • Apply macOS Tahoe update to version 26.5.2

Generated by OpenCVE AI on June 29, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 29 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Title Website-Rendered Content Permits Sensitive Data Leakage via Permissions Issue
Weaknesses CWE-284

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Visiting a website may leak sensitive data.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-06-29T19:42:53.590Z

Reserved: 2026-05-01T22:46:21.644Z

Link: CVE-2026-43713

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-29T21:30:03Z

Weaknesses