Description
This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may be able to silently hijack clipboard data.
Published: 2026-06-29
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Safari, iOS, iPadOS and macOS allows a malicious webpage to silently overwrite the user’s clipboard without visible indication. Once the clipboard contents are replaced, the attacker can capture or modify copy‑paste data used by other applications, causing unauthorized disclosure or tampering of private information.

Affected Systems

Apple products including Safari, iOS, iPadOS and macOS Tahoe are affected. The issue was fixed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2 and macOS Tahoe 26.5.2. Based on the patch version information, it is inferred that earlier releases are still vulnerable, though this is an inference.

Risk and Exploitability

The exploitation path is a user visiting a malicious website; no special privileges are required beyond normal web browsing. EPSS data is unavailable and the vulnerability is not listed in CISA KEV. The CVSS score is not supplied, but the flaw permits covert data extraction and can undermine confidentiality of sensitive information.

Generated by OpenCVE AI on June 29, 2026 at 22:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Safari to version 26.5.2 or later
  • Upgrade iOS and iPadOS to version 26.5.2 or later
  • Upgrade macOS Tahoe to version 26.5.2 or later

Generated by OpenCVE AI on June 29, 2026 at 22:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 29 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Title Malicious Website Clipboard Hijack via Improper State Management
Weaknesses CWE-200

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may be able to silently hijack clipboard data.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-06-29T19:43:10.464Z

Reserved: 2026-05-01T22:46:21.645Z

Link: CVE-2026-43721

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-29T22:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor