Impact
The vulnerability arose because the browser failed to enforce same‑origin checks reliably. A malicious webpage can read data that would normally be protected by the same‑origin policy, allowing it to exfiltrate information across origins. This represents a privacy breach that could expose any data the victim has stored in its browsing context.
Affected Systems
Apple Safari versions prior to 26.5.2, Apple iOS and iPadOS versions prior to 18.7.10 and prior to 26.5.2, Apple macOS Tahoe prior to 26.5.2, Apple tvOS prior to 26.6, Apple visionOS prior to 26.6, and Apple watchOS prior to 26.6 are impacted.
Risk and Exploitability
The EPSS score of < 1% indicates a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 8.1 reflects a high severity. The likely attack vector is a user visiting a malicious or compromised website that can read data cross‑origin; no elevated privileges or network control are required. With no confirmed public exploits, the current threat level is moderate, though the privacy impact could be high if the flaw were exploited.
OpenCVE Enrichment