Executive brief
Apple has released security updates for Safari, iOS, iPadOS, and macOS to address a vulnerability that could allow malicious websites to access sensitive user information. This issue occurs when the web browser or operating system fails to properly isolate data between different websites. Users are advised to update their devices to the latest versions to prevent potential data disclosure.
Technical details
A cross-origin vulnerability exists in Apple's web processing components due to insufficient tracking of security origins. An attacker can exploit this by enticing a user to visit a maliciously crafted website, potentially bypassing Same-Origin Policy (SOP) restrictions to access sensitive data from other origins. The issue was addressed through improved tracking of security origins in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2. While the advisory lists severity as 'info', cross-origin data disclosure typically warrants a medium severity rating in practical security contexts.
Affected products
- Apple Safari Before 26.5.2
- Apple iOS and iPadOS Before 26.5.2
- Apple macOS Tahoe Before 26.5.2
Timeline
- 2026-06-29: advisory: Initial disclosure by Apple and NVD publication.
- 2026-06-29: patched: Fixed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.