Impact
Based on the updated description, the flaw stems from improper state management that permits a malicious website to silently hijack or overwrite clipboard contents. Visiting an affected site can cause the website to capture whatever the user has copied or to replace the clipboard after a copy action without the user’s awareness. This leads to covert theft of sensitive data such as passwords and credit card numbers, and corresponds to a permissions assignment weakness (CWE‑732).
Affected Systems
Apple Safari, iOS, iPadOS, macOS (Tahoe), tvOS, visionOS and watchOS are impacted. Any version earlier than Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, or watchOS 26.6 contains the bug. Upgrading to the listed patched releases eliminates the ability for a website to hijack clipboard data.
Risk and Exploitability
Exploitation requires only a user to navigate to a malicious webpage; no special privileges or configuration are needed. The EPSS score of less than 1 % suggests that current exploitation attempts are rare, yet the CVSS score of 6.5 assigns high severity because an attacker can covertly retrieve clipboard data, compromising confidentiality. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread deployment of exploit code at this time.
OpenCVE Enrichment
Debian DSA