Impact
The vulnerability enables a maliciously crafted website to cause an Apple device to leak sensitive user data when accessed. Apple addressed the issue with improved checks, and the fix is included in iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2. An attacker who can host or direct a user to a malicious site can potentially read data the user did not intend to share.
Affected Systems
The flaw impacts Apple devices running iOS or iPadOS before the patched releases, specifically any iOS or iPadOS version earlier than 18.7.10, as well as earlier releases up to 26.6.1. macOS Tahoe versions older than 26.6.2 are also affected.
Risk and Exploitability
Visiting a maliciously crafted website may trigger the data leak, meaning the attack vector is remote via web browsing and requires only user interaction to exploit. Because the exploit can be triggered simply by navigating to a crafted page, the barrier to exploitation is low from the attacker’s perspective. The EPSS score is currently unavailable and the vulnerability is not listed in the CISA KEV catalog, but the straightforward attack path suggests a realistic risk of exploitation.
OpenCVE Enrichment