Impact
A permissions issue was addressed with additional restrictions; however, a malicious website can still exploit the flaw by visiting a page, potentially causing leakage of sensitive data such as cookies, local storage, or credentials. The weakness stems from insufficient permission checks and is classified as CWE‑284, highlighting a lack of proper authorization controls. This results in a data leakage scenario that compromises user privacy without enabling code execution.
Affected Systems
Apple Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS running versions earlier than the fixes are affected. The vulnerability is resolved in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6, where the excessive permission is revoked.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity, and the EPSS score of < 1% reflects a very low known exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attack is likely via a malicious or compromised website that a user visits; the attacker needs no special privileges beyond loading a URL. No exploit evidence is reported, suggesting the risk is largely theoretical, but the potential for data exposure warrants prompt patching.
OpenCVE Enrichment
Debian DSA