Description
The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Visiting a website that frames malicious content may lead to UI spoofing.
Published: 2026-07-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS may render malicious content inside iframes in a way that manipulates the user interface, creating a spoofed visual environment that could mislead users into believing they are interacting with legitimate content. This weakness allows an attacker to entice users into providing information or performing actions on fabricated controls without granting the attacker any direct code execution or access to system files. The impact is therefore primarily a social engineering risk, compromising the integrity of the user experience and potentially facilitating phishing or credential theft.

Affected Systems

All Apple products that had the browser or operating system prior to version 26.6 are affected. This includes Safari on macOS, iOS, iPadOS, tvOS, visionOS, and watchOS. Installations of these platforms that have not applied the 26.6 release are vulnerable. Apple supplies fixes in Safari 26.6, iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Risk and Exploitability

The vulnerability is reachable via a web page that serves frame content; it does not require any local privileges or exploitation of DLLs or binaries. Because the attacker must simply host a malicious site that the victim visits, this is a relatively low barrier attack, although it relies on user interaction. No public exploit has yet been observed, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score of < 1% indicates a very low probability of exploitation in the wild. With a CVSS score of 6.5, the overall risk is considered medium: the attacker can induce deceptive behavior but cannot directly compromise the device. Installing the official patches removes the vulnerability and eliminates the risk of UI spoofing.

Generated by OpenCVE AI on August 4, 2026 at 13:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Apple update to Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS to version 26.6 or later.
  • If an update is not immediately possible, avoid browsing sites that embed iframes or known malicious content and consult Apple’s security advisories for additional mitigation measures.
  • As a temporary measure, configure browser settings or use extensions that block or restrict iframe loading from external domains.

Generated by OpenCVE AI on August 4, 2026 at 13:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Framing on Apple Safari and Operating Systems
Weaknesses CWE-1054

Thu, 30 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Framing on Apple Safari and Operating Systems
Weaknesses CWE-1054

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Visiting a website that frames malicious content may lead to UI spoofing.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:04:05.762Z

Reserved: 2026-07-20T18:09:47.193Z

Link: CVE-2026-64730

cve-icon Vulnrichment

Updated: 2026-07-28T14:03:55.906Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:11.930

Modified: 2026-07-28T18:48:50.317

Link: CVE-2026-64730

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:30:10Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information