Impact
The vulnerability allows a malicious website to bypass the browser’s same‑origin checks, enabling the exfiltration of data that resides on other origins in the victim’s browser. The flaw is reflected in the CWE-352 classification. Because the same‑origin policy is bypassed, a site can read information that is meant to be isolated between different origins, leading to a privacy breach.
Affected Systems
Apple Safari versions prior to 26.5.2, Apple iOS and iPadOS versions prior to 26.5.2, Apple macOS Tahoe prior to 26.5.2, Apple tvOS prior to 26.6, Apple visionOS prior to 26.6, and Apple watchOS prior to 26.6 are impacted. The issue is fixed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The EPSS score of < 1% indicates a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 8.1 reflects a high severity. The likely attack vector is a user visiting a malicious or compromised website that can read data cross‑origin; no elevated privileges or network control are required. With no confirmed public exploits, the current threat level is moderate, though the privacy impact could be high if the flaw were exploited.
OpenCVE Enrichment