Junglewise Threat Intelligence

CVE-2026-43713: Apple Safari and OS permissions issue leads to sensitive data leak

CVE-2026-43713 · Severity: info · Published 2026-06-29

Technologies: Apple Safari, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A security issue in Apple's Safari browser and operating systems (iOS, iPadOS, and macOS) could allow malicious websites to access sensitive user data. This occurs due to insufficient permission restrictions when a user visits a compromised or specially crafted website. Exploitation could lead to the unauthorized exposure of private information.

Technical details

A permissions vulnerability exists in Apple Safari and the underlying operating systems (iOS, iPadOS, and macOS Tahoe) due to insufficient restrictions. An attacker can exploit this by enticing a user to visit a malicious website, which could then trigger the leakage of sensitive data. The vulnerability was mitigated by implementing stricter permission checks and additional restrictions within the affected components. The issue is resolved in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.

Affected products

  • Apple Safari < 26.5.2
  • Apple iOS and iPadOS < 26.5.2
  • Apple macOS Tahoe < 26.5.2

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: patched

References

Related threats