Impact
A logic flaw in the state management of Apple’s web browsers and operating systems allows an attacker to trigger universal cross‑site scripting by providing a specially crafted webarchive file. This vulnerability can inject arbitrary JavaScript into any web page the victim visits, potentially exposing credentials, session data, or other sensitive information the site holds. The flaw does not directly allow remote code execution but enables the attacker to execute code in the context of the victim’s browser.
Affected Systems
The issue affects Apple Safari, iOS, iPadOS, macOS (Golden Gate), and visionOS. All versions prior to Safari 27, iOS 27, iPadOS 27, macOS Golden Gate 27, and visionOS 27.
Risk and Exploitability
Because the attack vector requires the victim to open a malicious webarchive file, an attacker could employ social‑engineering methods such as phishing emails or malicious downloads to deliver the file. Once opened, the exploit would execute in the browser context, providing broad access to the user’s browsing environment. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the potential impact of cross‑site scripting remains significant for affected users.
OpenCVE Enrichment