Description
A permissions issue was addressed with improved validation. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Maliciously crafted web content may violate iframe sandboxing policy.
Published: 2026-07-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A permissions flaw in Safari and Apple operating systems allows maliciously crafted web content to violate the iframe sandboxing policy. The failure of access control means that content can run with privileges it normally could not obtain inside the browser context, potentially enabling scripts or resources to access or manipulate elements that should be protected by the sandbox.

Affected Systems

Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. Version numbers below 26.6 are vulnerable; the issue was fixed in Safari 26.6, iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of <1% shows a very low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed by CISA in the KEV catalog. Exploitation would likely involve a user accessing or loading malicious web content in Safari or an embedded web view, thereby bypassing the iframe sandbox policy to run privileged code within the browser environment.

Generated by OpenCVE AI on August 4, 2026 at 13:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all affected Apple products to version 26.6 or later.
  • If an update cannot be applied immediately, restrict web content to trusted domains or apply strict content‑security policies that prevent iframe sandbox bypass attempts.
  • Enable automatic system updates to receive future patches as soon as they become available.

Generated by OpenCVE AI on August 4, 2026 at 13:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Safari and Apple OS iframe sandbox bypass
Weaknesses CWE-285

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Safari and Apple OS iframe sandbox bypass
Weaknesses CWE-285
CWE-693
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with improved validation. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Maliciously crafted web content may violate iframe sandboxing policy.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T15:10:57.316Z

Reserved: 2026-07-20T18:09:47.192Z

Link: CVE-2026-64728

cve-icon Vulnrichment

Updated: 2026-07-28T15:10:43.268Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:11.737

Modified: 2026-07-28T18:55:20.553

Link: CVE-2026-64728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:45:03Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure