Executive brief
A vulnerability in Apple's web browser and operating systems could allow a malicious website to steal data from other websites you have open. This occurs because the software does not properly isolate information between different web origins. If exploited, an attacker could exfiltrate sensitive user information or session data while a user is browsing the web.
Technical details
A cross-origin data exfiltration vulnerability exists in Apple Safari, iOS, iPadOS, and macOS Tahoe. The root cause is insufficient input validation within the browser engine, which fails to strictly enforce origin boundaries. A remote attacker can exploit this by enticing a user to visit a specially crafted malicious website. Successful exploitation allows the attacker to exfiltrate sensitive data across origins, potentially compromising user sessions or private information. The issue has been addressed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2 through improved input validation.
Affected products
- Apple Safari Before 26.5.2
- Apple iOS and iPadOS Before 26.5.2
- Apple macOS Tahoe Before 26.5.2
Timeline
- 2026-06-29: disclosed
- 2026-06-29: advisory
- 2026-06-29: patched