Impact
A malicious website may be able to process restricted web content outside the sandbox, allowing a potential breach of browser isolation. The flaw stems from insufficient validation of input and has been patched by improving validation logic. The fix applies to Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6 and watchOS 26.6.
Affected Systems
Apple products including Safari, iOS, iPadOS, macOS, tvOS, visionOS and watchOS are impacted. Any device running a version earlier than Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6 or watchOS 26.6 is vulnerable and should be updated to the stated fixes.
Risk and Exploitability
The EPSS score is 0.00829 (< 1%) and the vulnerability is not listed in the CISA KEV catalog, indicating no current widespread exploitation. The attack vector is inferred to be a malicious website accessed through the browser. An attacker would need to host or lure a victim to a web page that exploits this input validation flaw; no user interaction beyond normal browsing is noted in the description. The CVSS score is 7.1.
OpenCVE Enrichment
Debian DSA