Executive brief
A security issue in Apple's web browser and operating systems could allow a malicious website to intercept communications intended for other sites. This could lead to the unauthorized access of sensitive data handled by web scripts. Users are advised to update their devices to the latest software versions to resolve this logic error.
Technical details
A logic issue exists in the state management of script message handlers across multiple Apple platforms. An attacker can exploit this by hosting a malicious website that, when visited by a user, accesses message handlers intended for different web origins (CWE-346). This bypasses intended origin isolation, potentially allowing the theft of sensitive information processed by those handlers. The issue is resolved in Safari 26.4, iOS/iPadOS 18.7.7, iOS/iPadOS 26.4, macOS Tahoe 26.4, and visionOS 26.4 through improved state management logic.
Affected products
- Apple Safari < 26.4
- Apple iOS and iPadOS < 18.7.7, 26.0 to < 26.4
- Apple macOS < 26.4
- Apple visionOS < 26.4
Timeline
- 2026-03-25: disclosed: Initial publication date
- 2026-03-25: patched: Fixes released in Safari 26.4 and related OS updates