Impact
The CVE describes a path‑handling issue that, due to insufficient validation, may disclose sensitive user information when malicious web content is processed. Apple addressed the flaw with improved validation in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS 26.5.2 (Tahoe), tvOS 26.6, visionOS 26.6, and watchOS 26.6. The vulnerability allows an attacker to trigger the path‑handling flaw via crafted web content and potentially expose confidential files or data on the device.
Affected Systems
Apple Safari on macOS, iOS, iPadOS, tvOS, visionOS, and watchOS are affected when running the affected versions (Safari 26.5.2 or earlier, iOS 26.5.2 or earlier, iPadOS 26.5.2 or earlier, macOS 26.5.2 or earlier, and tvOS, visionOS, watchOS 26.6 or earlier). The issue is fixed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. Devices running earlier releases are vulnerable to disclosure of user data via the path‑handling flaw.
Risk and Exploitability
The EPSS score of < 1% suggests a low yet nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 indicates moderate severity. The most likely attack vector is the delivery of malicious web content through Safari (or related Apple web components), which could trigger the path‑handling flaw and leak sensitive data.
OpenCVE Enrichment
Debian DSA