Impact
A flaw in WebKit’s handling of link visitation data allows a website to detect whether a user has previously visited a given URL, thereby revealing the browsing history of the user to third‑party sites. This constitutes an information‑disclosure vulnerability that can expose sensitive navigation patterns.
Affected Systems
Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS and watchOS running a version earlier than 26.6 are affected. The vulnerability is fixed in Safari 26.6, iOS 26.6 / iPadOS 26.6, macOS 26.6, tvOS 26.6, visionOS 26.6 and watchOS 26.6.
Risk and Exploitability
The EPSS score (<1%) indicates a very low probability of exploitation, while the CVSS score of 8.1 demonstrates high severity. Based on the description, it is inferred that the attack requires a malicious website presenting a crafted page to the user, making the vector browser‑based and dependent on user interaction, which reduces the likelihood of widespread exploitation. The issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DSA
Ubuntu USN