Description
The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may exfiltrate data cross-origin.
Published: 2026-06-29
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allowed a malicious website to bypass the browser’s same‑origin policy, enabling exfiltration of data that resides on other origins in the victim’s browser. This privacy leak could reveal sensitive information such as cookies, local storage entries, or other user data that should remain isolated between websites. The weakness is reflected in the CWE‑1021 classification for improper CORS handling and applies to Apple WebKit components.

Affected Systems

Apple Safari, iOS, iPadOS and macOS Tahoe are impacted. The issue existed in versions preceding Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2 and macOS Tahoe 26.5.2. The fix was delivered in those 26.5.2 releases for all listed products.

Risk and Exploitability

The EPSS score of 0.00168 indicates a very low but nonzero probability that the vulnerability will be exploited. The vulnerability is not listed in the CISA KEV catalog, suggesting that no confirmed exploitation has occurred to date. The likely attack vector is a user visiting a malicious or compromised website that can read data cross‑origin; no elevated privileges or network control appear required. While the CVSS score is not provided, the privacy impact of leaking data across origins represents a moderate to high risk if exploited, and with no known public exploits the current threat level is considered moderate until a new exploit emerges.

Generated by OpenCVE AI on June 30, 2026 at 16:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Apple devices to Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2 or macOS Tahoe 26.5.2, which add the missing checks that prevent cross‑origin data access.
  • On managed systems, enforce a strict WebKit Content Security Policy or control Access‑Control‑Allow‑Origin headers to limit cross‑origin requests until the update is applied.
  • Review any third‑party web content or web‑view components for improper CORS configuration and correct them if necessary.

Generated by OpenCVE AI on June 30, 2026 at 16:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 30 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Title Apple Safari and iOS Cross‑Origin Data Exfiltration Vulnerability

Tue, 30 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Tue, 30 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari

Mon, 29 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Title Apple Safari and iOS Cross‑Origin Data Exfiltration Vulnerability
Weaknesses CWE-1021
CWE-79

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may exfiltrate data cross-origin.
References

Subscriptions

Apple Ios And Ipados Macos Safari
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-06-30T15:08:35.103Z

Reserved: 2026-05-01T22:46:21.646Z

Link: CVE-2026-43735

cve-icon Vulnrichment

Updated: 2026-06-30T13:39:38.868Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-30T16:30:16Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames

  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')