Description
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose sensitive user information.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Disclosure
Action: Apply Update
AI Analysis

Impact

A permissions flaw in Safari and the associated Apple operating systems allows a malicious web page to trigger code that can read or reveal user data that the application should not expose. This vulnerability can compromise the confidentiality of personal information such as credentials, browsing history, or other sensitive data held by the system. The weakness is grounded in improper authorization controls (CWE-269) and sensitive data exposure (CWE-359). The impact is limited to data leakage and does not provide direct code execution or control over the operating system.

Affected Systems

Apple Safari, Apple iOS, Apple iPadOS, Apple macOS, Apple tvOS, Apple visionOS, and Apple watchOS. The vulnerability is known to exist in builds that predate the fix is applied in Safari 27, iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. It is inferred that any version older than 27 could be affected because those versions lack the patch that removed the vulnerable code.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium-risk vulnerability, while an EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The issue is not listed in the CISA KEV catalog, implying that no public exploits have been recorded. The likely attack vector is the delivery of a crafted web page that takes advantage of the weakened permissions logic to access protected data. Given the absence of known exploits and the passive nature of the attack, the overall risk is moderate, but all exposed Apple devices should apply the available patch to eliminate the possibility of data leakage.

Generated by OpenCVE AI on September 20, 2026 at 21:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest OS and Safari update (version 27) on all Apple devices.
  • Use enterprise Mobile Device Management patched software can launch Safari, or block Safari until the update is installed.
  • Configure Safari to its most restrictive security settings, disabling or limiting JavaScript and other active content that could activate the vulnerable code.

Generated by OpenCVE AI on September 20, 2026 at 21:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6534-1 webkit2gtk security update
History

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title webkitgtk: Processing maliciously crafted web content may disclose sensitive user information
Weaknesses CWE-359
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 16 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Sensitive Data Disclosure via Safari Permissions Vulnerability
Weaknesses CWE-284
CWE-668

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Sensitive Data Disclosure via Safari Permissions Vulnerability
Weaknesses CWE-284
CWE-668

Tue, 15 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose sensitive user information.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T14:29:24.982Z

Reserved: 2026-07-20T18:10:30.632Z

Link: CVE-2026-64753

cve-icon Vulnrichment

Updated: 2026-09-15T14:29:19.313Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:14.880

Modified: 2026-09-15T19:29:58.910

Link: CVE-2026-64753

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-14T20:48:40Z

Links: CVE-2026-64753 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:15:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-359

    Exposure of Private Personal Information to an Unauthorized Actor