Impact
Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS may render malicious content inside iframes in a way that manipulates the user interface, creating a spoofed visual environment that could mislead users into believing they are interacting with legitimate content. This weakness allows an attacker to entice users into providing information or performing actions on fabricated controls without granting the attacker any direct code execution or access to system files. The impact is therefore primarily a social engineering risk, compromising the integrity of the user experience and potentially facilitating phishing or credential theft.
Affected Systems
All Apple products that had the browser or operating system prior to version 26.6 are affected. This includes Safari on macOS, iOS, iPadOS, tvOS, visionOS, and watchOS. Installations of these platforms that have not applied the 26.6 release are vulnerable. Apple supplies fixes in Safari 26.6, iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The vulnerability is reachable via a web page that serves frame content; it does not require any local privileges or exploitation of DLLs or binaries. Because the attacker must simply host a malicious site that the victim visits, this is a relatively low barrier attack, although it relies on user interaction. No public exploit has yet been observed, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score of < 1% indicates a very low probability of exploitation in the wild. With a CVSS score of 6.5, the overall risk is considered medium: the attacker can induce deceptive behavior but cannot directly compromise the device. Installing the official patches removes the vulnerability and eliminates the risk of UI spoofing.
OpenCVE Enrichment