Description
The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin.
Published: 2026-06-29
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a malicious website to bypass the browser’s same‑origin checks, enabling the exfiltration of data that resides on other origins in the victim’s browser. The flaw is reflected in the CWE-352 classification. Because the same‑origin policy is bypassed, a site can read information that is meant to be isolated between different origins, leading to a privacy breach.

Affected Systems

Apple Safari versions prior to 26.5.2, Apple iOS and iPadOS versions prior to 26.5.2, Apple macOS Tahoe prior to 26.5.2, Apple tvOS prior to 26.6, Apple visionOS prior to 26.6, and Apple watchOS prior to 26.6 are impacted. The issue is fixed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Risk and Exploitability

The EPSS score of < 1% indicates a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 8.1 reflects a high severity. The likely attack vector is a user visiting a malicious or compromised website that can read data cross‑origin; no elevated privileges or network control are required. With no confirmed public exploits, the current threat level is moderate, though the privacy impact could be high if the flaw were exploited.

Generated by OpenCVE AI on August 4, 2026 at 18:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Apple devices to Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6 to include the missing same‑origin checks.
  • If an update cannot be applied immediately, restrict cross‑origin data access in managed environments by configuring a Content Security Policy that blocks third‑party script and resource loads or by disabling third‑party web‑view components until the update is available.
  • Monitor for signs of exploitation and review any third‑party web content or embedded web views for improper CORS configuration, correcting any issues that are found.

Generated by OpenCVE AI on August 4, 2026 at 18:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Exfiltration via Improper Same‑Origin Checks in Apple WebKit

Mon, 03 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Exfiltration via Improper Same‑Origin Checks in Apple WebKit
Weaknesses CWE-1021
CWE-79

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may exfiltrate data cross-origin. The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin.
References

Tue, 30 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Title Apple Safari and iOS Cross‑Origin Data Exfiltration Vulnerability

Tue, 30 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Tue, 30 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari

Mon, 29 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Title Apple Safari and iOS Cross‑Origin Data Exfiltration Vulnerability
Weaknesses CWE-1021
CWE-79

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may exfiltrate data cross-origin.
References

Subscriptions

Apple Ios And Ipados Macos Safari
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-27T20:12:12.200Z

Reserved: 2026-05-01T22:46:21.646Z

Link: CVE-2026-43735

cve-icon Vulnrichment

Updated: 2026-06-30T13:39:38.868Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T19:00:10Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)