Description
A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may disclose sensitive user information.
Published: 2026-06-29
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE describes a path‑handling issue that, due to insufficient validation, may disclose sensitive user information when malicious web content is processed. Apple addressed the flaw with improved validation in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS 26.5.2 (Tahoe), tvOS 26.6, visionOS 26.6, and watchOS 26.6. The vulnerability allows an attacker to trigger the path‑handling flaw via crafted web content and potentially expose confidential files or data on the device.

Affected Systems

Apple Safari on macOS, iOS, iPadOS, tvOS, visionOS, and watchOS are affected when running the affected versions (Safari 26.5.2 or earlier, iOS 26.5.2 or earlier, iPadOS 26.5.2 or earlier, macOS 26.5.2 or earlier, and tvOS, visionOS, watchOS 26.6 or earlier). The issue is fixed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. Devices running earlier releases are vulnerable to disclosure of user data via the path‑handling flaw.

Risk and Exploitability

The EPSS score of < 1% suggests a low yet nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 indicates moderate severity. The most likely attack vector is the delivery of malicious web content through Safari (or related Apple web components), which could trigger the path‑handling flaw and leak sensitive data.

Generated by OpenCVE AI on August 3, 2026 at 07:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS devices to the latest security patches (Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6).
  • Implement an automated device update policy to ensure that the latest security patches are installed promptly, preventing exposure to the vulnerability.
  • Use enterprise content filtering or web security tools to restrict malicious web content until the update propagates, thereby reducing the risk of exploitation via Safari.

Generated by OpenCVE AI on August 3, 2026 at 07:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6398-1 webkit2gtk security update
History

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may disclose sensitive user information. A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may disclose sensitive user information.
References

Fri, 17 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title webkitgtk: webkitgtk: Maliciously crafted web content may disclose sensitive user information
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 30 Jun 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari

Tue, 30 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Title Path Handling Vulnerability in Apple Safari Enables Sensitive Information Disclosure

Mon, 29 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Title Path Handling Vulnerability in Apple Safari Enables Sensitive Information Disclosure
Weaknesses CWE-22

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may disclose sensitive user information.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Safari
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-27T20:13:32.035Z

Reserved: 2026-05-01T22:46:21.646Z

Link: CVE-2026-43732

cve-icon Vulnrichment

Updated: 2026-06-29T21:30:50.434Z

cve-icon NVD

Status : Modified

Published: 2026-06-29T20:17:37.317

Modified: 2026-07-27T21:16:57.843

Link: CVE-2026-43732

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-10T00:00:00Z

Links: CVE-2026-43732 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T07:15:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')