Executive brief
A vulnerability in Apple's Safari web browser and operating systems (iOS, iPadOS, and macOS) could allow a malicious website to access restricted web content. This bypasses the security 'sandbox' designed to keep web activities isolated from the rest of the system. If exploited, this could lead to the unauthorized processing of sensitive data or interaction with internal web components.
Technical details
A sandbox escape vulnerability exists in Apple's WebKit-based products, including Safari and the underlying operating systems iOS, iPadOS, and macOS. The flaw is caused by insufficient checks when handling restricted web content, allowing a malicious site to bypass sandbox boundaries. An attacker can exploit this by enticing a user to visit a specially crafted website, potentially leading to the unauthorized processing of sensitive web data or access to restricted resources. The issue was addressed by implementing improved validation checks in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.
Affected products
- Apple Safari < 26.5.2
- Apple iOS and iPadOS < 26.5.2
- Apple macOS Tahoe < 26.5.2
Timeline
- 2026-06-29: disclosed
- 2026-06-29: patched