Description
This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Websites may know if the user has visited a given link.
Published: 2026-07-27
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in WebKit’s handling of link visitation data allows a website to detect whether a user has previously visited a given URL, thereby revealing the browsing history of the user to third‑party sites. This constitutes an information‑disclosure vulnerability that can expose sensitive navigation patterns.

Affected Systems

Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS and watchOS running a version earlier than 26.6 are affected. The vulnerability is fixed in Safari 26.6, iOS 26.6 / iPadOS 26.6, macOS 26.6, tvOS 26.6, visionOS 26.6 and watchOS 26.6.

Risk and Exploitability

The EPSS score (<1%) indicates a very low probability of exploitation, while the CVSS score of 8.1 demonstrates high severity. Based on the description, it is inferred that the attack requires a malicious website presenting a crafted page to the user, making the vector browser‑based and dependent on user interaction, which reduces the likelihood of widespread exploitation. The issue is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 22, 2026 at 11:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Apple software update that includes Safari 26.6, iOS 26.6 / iPadOS 26.6 / macOS 26.6 / tvOS 26.6 / visionOS 26.6 / watchOS 26.6 on all affected devices.
  • Enable Automatic Updates on all Apple devices so that future patches are applied as soon as they become available.
  • If devices are managed via MDM or other management tools, configure compliance enforcement to flag and remediate any device that remains on a pre‑26.6 version.

Generated by OpenCVE AI on August 22, 2026 at 11:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6463-1 webkit2gtk security update
Ubuntu USN Ubuntu USN USN-8703-1 WebKitGTK vulnerabilities
History

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Browser Link Visitation Information Disclosure webkitgtk: Websites may know if the user has visited a given link
Weaknesses CWE-200
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 13 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Browser Link Visitation Information Disclosure

Wed, 12 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Title Browser History Leakage via Link Visit Detection
Weaknesses CWE-200

Tue, 04 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Browser History Leakage via Link Visit Detection
Weaknesses CWE-200

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Privacy Leak Allowing Websites to Detect Previously Visited Links
Weaknesses CWE-200

Thu, 30 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Privacy Leak Allowing Websites to Detect Previously Visited Links
Weaknesses CWE-200

Tue, 28 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Websites may know if the user has visited a given link.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T19:11:08.015Z

Reserved: 2026-07-20T18:09:35.084Z

Link: CVE-2026-64713

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:10.560

Modified: 2026-07-30T14:34:30.697

Link: CVE-2026-64713

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-20T00:00:00Z

Links: CVE-2026-64713 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T11:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-203

    Observable Discrepancy