Impact
The vulnerability stems from improper state management that allows a malicious webpage to silently overwrite the clipboard contents. Based on the description, it is inferred that an attacker can replace the user’s data without visible indication, leading to unauthorized disclosure or tampering of sensitive information that the victim copies or pastes. This flaw resides in a permission assignment bug, aligning with CWE-732.
Affected Systems
Apple Safari, iOS, iPadOS, and macOS Tahoe are affected when running any version earlier than 26.5.2. Version 26.5.2 and later contain the fix that corrects the state-management issue, eliminating the possibility of this clipboard hijack.
Risk and Exploitability
Exploitation appears to require only a user visiting a malicious site, with no special privileges or configuration needed. The EPSS score is less than 1% indicating a low current likelihood of exploitation, but the CVSS score of 6.5 designates high severity because an attacker can covertly steal clipboard data, compromising confidentiality and potentially revealing personal or sensitive information. The vulnerability is not listed in CISA KEV.
OpenCVE Enrichment