Impact
The issue was addressed with improved checks. A maliciously crafted website can cause an Apple device to leak sensitive data when visited. The fix is included in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, and macOS Tahoe 26.6.2. An attacker who can host or direct a user to a malicious site can thereby read data the user did not intend to share.
Affected Systems
The flaw impacts Apple devices running iOS or iPadOS before the patched releases, specifically any iOS or iPadOS version earlier than 18.7.10, as well as earlier releases up to 26.6.1. macOS Tahoe versions older than 26.6.2 are also affected.
Risk and Exploitability
Visiting a maliciously crafted website may trigger the data leak, meaning the attack vector is remote via web browsing and requires only user interaction to exploit. Because the exploit can be triggered simply by navigating to a crafted page, the barrier to exploitation is low from the attacker’s perspective. The CVSS score is 6.5, the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a moderate likelihood of exploitation but still a realistic threat due to the simple attack path.
OpenCVE Enrichment