Description
The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin.
Published: 2026-06-29
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arose because the browser failed to enforce same‑origin checks reliably. A malicious webpage can read data that would normally be protected by the same‑origin policy, allowing it to exfiltrate information across origins. This represents a privacy breach that could expose any data the victim has stored in its browsing context.

Affected Systems

Apple Safari versions prior to 26.5.2, Apple iOS and iPadOS versions prior to 18.7.10 and prior to 26.5.2, Apple macOS Tahoe prior to 26.5.2, Apple tvOS prior to 26.6, Apple visionOS prior to 26.6, and Apple watchOS prior to 26.6 are impacted.

Risk and Exploitability

The EPSS score of < 1% indicates a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 8.1 reflects a high severity. The likely attack vector is a user visiting a malicious or compromised website that can read data cross‑origin; no elevated privileges or network control are required. With no confirmed public exploits, the current threat level is moderate, though the privacy impact could be high if the flaw were exploited.

Generated by OpenCVE AI on August 17, 2026 at 22:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Apple devices to Safari 26.5.2, iOS 18.7.10, iOS 26.5.2, iPadOS 18.7.10, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6 to include the missing same‑origin checks.
  • If an update cannot be applied immediately, restrict cross‑origin data access in managed environments by configuring a Content Security Policy that blocks third‑party script and resource loads or by disabling third‑party web‑view components until the update is available.
  • Monitor for signs of exploitation and review any third‑party web content or embedded web views for improper CORS configuration, correcting any issues that are found.

Generated by OpenCVE AI on August 17, 2026 at 22:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Safari and iOS Browsers Allow Cross‑Origin Data Exfiltration via Same‑Origin Policy Bypass

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin. The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin.
References

Tue, 04 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Exfiltration via Improper Same‑Origin Checks in Apple WebKit

Mon, 03 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Exfiltration via Improper Same‑Origin Checks in Apple WebKit
Weaknesses CWE-1021
CWE-79

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may exfiltrate data cross-origin. The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin.
References

Tue, 30 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Title Apple Safari and iOS Cross‑Origin Data Exfiltration Vulnerability

Tue, 30 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Tue, 30 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari

Mon, 29 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Title Apple Safari and iOS Cross‑Origin Data Exfiltration Vulnerability
Weaknesses CWE-1021
CWE-79

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may exfiltrate data cross-origin.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Safari
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:29:18.176Z

Reserved: 2026-05-01T22:46:21.646Z

Link: CVE-2026-43735

cve-icon Vulnrichment

Updated: 2026-06-30T13:39:38.868Z

cve-icon NVD

Status : Modified

Published: 2026-06-29T20:17:37.507

Modified: 2026-08-17T22:17:09.863

Link: CVE-2026-43735

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T23:00:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)