Description
An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to access sensitive user data.
Published: 2026-07-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authorization flaw in Apple Safari and macOS allows an application to read sensitive user data by exploiting improper state management. The vulnerability can lead to privacy violations without requiring elevated credentials, and the weakness corresponds to CWE-284 and CWE-285.

Affected Systems

Apple Safari versions prior to 26.6 and macOS Tahoe 26.6 are affected. Earlier releases of Safari and macOS that have not been upgraded to these versions remain vulnerable.

Risk and Exploitability

The CVSS score is 6.5, indicating moderate severity. The EPSS score is below 1 %, showing a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely local, where a malicious or compromised application running on the device could interact with the Safari state handling mechanism. Because no privileged access is required, the risk is primarily to user privacy.

Generated by OpenCVE AI on August 2, 2026 at 10:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Safari 26.6 or later.
  • Upgrade macOS to 26.6 or later.
  • Avoid using third‑party applications that may access legacy Safari state until a full fix is deployed.
  • Review and restrict app permissions that involve web browsing or Safari data.

Generated by OpenCVE AI on August 2, 2026 at 10:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Authorization Issue Allowing Apps to Access Sensitive Data in Safari and macOS

Wed, 29 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Authorization Issue Allowing Apps to Access Sensitive Data in Safari and macOS
Weaknesses CWE-284

Tue, 28 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Apple safari
Vendors & Products Apple
Apple macos
Apple safari

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T18:51:57.213Z

Reserved: 2026-05-01T22:46:27.820Z

Link: CVE-2026-43792

cve-icon Vulnrichment

Updated: 2026-07-28T18:51:53.005Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:02.700

Modified: 2026-07-29T20:28:58.380

Link: CVE-2026-43792

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T10:15:03Z

Weaknesses