Impact
A permissions flaw in Safari and the associated Apple operating systems allows a malicious web page to trigger code that can read or reveal user data that the application should not expose. This vulnerability can compromise the confidentiality of personal information such as credentials, browsing history, or other sensitive data held by the system. The weakness is grounded in improper authorization controls (CWE-269) and sensitive data exposure (CWE-359). The impact is limited to data leakage and does not provide direct code execution or control over the operating system.
Affected Systems
Apple Safari, Apple iOS, Apple iPadOS, Apple macOS, Apple tvOS, Apple visionOS, and Apple watchOS. The vulnerability is known to exist in builds that predate the fix is applied in Safari 27, iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. It is inferred that any version older than 27 could be affected because those versions lack the patch that removed the vulnerable code.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium-risk vulnerability, while an EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The issue is not listed in the CISA KEV catalog, implying that no public exploits have been recorded. The likely attack vector is the delivery of a crafted web page that takes advantage of the weakened permissions logic to access protected data. Given the absence of known exploits and the passive nature of the attack, the overall risk is moderate, but all exposed Apple devices should apply the available patch to eliminate the possibility of data leakage.
OpenCVE Enrichment
Debian DSA