Executive brief
A vulnerability in Apple's web browser engine could allow a malicious website to interfere with how files are downloaded. By using a hidden frame, an attacker's site could inherit or manipulate the download settings of a different, legitimate website. This could lead to files being saved in unexpected locations or with incorrect security settings without the user's knowledge.
Technical details
A logic vulnerability exists in the UI handling of iframes across multiple Apple platforms. A malicious website can utilize an iframe to inherit or leverage the download settings associated with a different origin. This issue stems from inconsistent state management or improper isolation of download preferences between parent and child frames. An attacker could exploit this by tricking a user into visiting a malicious page that embeds a target site in an iframe to manipulate download behavior. The issue was addressed by improving UI handling and state management in Safari 26.5 and related OS updates.
Affected products
- Apple iOS < 26.5
- Apple iPadOS < 26.5
- Apple macOS Tahoe < 26.5
- Apple visionOS < 26.5
- Apple Safari < 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched