Executive brief
A vulnerability in Apple's Safari browser and operating systems could allow a malicious website to silently access and steal information from a user's clipboard. This means sensitive data like passwords or personal messages copied by the user could be captured without their knowledge while browsing. Users should update their Apple devices to the latest software versions to prevent this unauthorized data access.
Technical details
A vulnerability exists in Apple Safari and various Apple operating systems (iOS, iPadOS, macOS) where a malicious website can silently hijack clipboard data. The root cause is a state management issue that fails to properly restrict clipboard access. An attacker can exploit this by enticing a user to visit a specially crafted website, allowing the site to read the contents of the system clipboard without user interaction or notification. This issue was addressed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2 through improved state management.
Affected products
- Apple Safari before 26.5.2
- Apple iOS and iPadOS before 26.5.2
- Apple macOS Tahoe before 26.5.2
Timeline
- 2026-06-29: disclosed
- 2026-06-29: patched