Impact
The vulnerability allowed a malicious website to bypass the browser’s same‑origin policy, enabling exfiltration of data that resides on other origins in the victim’s browser. This privacy leak could reveal sensitive information such as cookies, local storage entries, or other user data that should remain isolated between websites. The weakness is reflected in the CWE‑1021 classification for improper CORS handling and applies to Apple WebKit components.
Affected Systems
Apple Safari, iOS, iPadOS and macOS Tahoe are impacted. The issue existed in versions preceding Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2 and macOS Tahoe 26.5.2. The fix was delivered in those 26.5.2 releases for all listed products.
Risk and Exploitability
The EPSS score of 0.00168 indicates a very low but nonzero probability that the vulnerability will be exploited. The vulnerability is not listed in the CISA KEV catalog, suggesting that no confirmed exploitation has occurred to date. The likely attack vector is a user visiting a malicious or compromised website that can read data cross‑origin; no elevated privileges or network control appear required. While the CVSS score is not provided, the privacy impact of leaking data across origins represents a moderate to high risk if exploited, and with no known public exploits the current threat level is considered moderate until a new exploit emerges.
OpenCVE Enrichment