Executive brief
A security issue in Apple's web browser and operating systems could allow a malicious website to access sensitive user information. This occurs when the system incorrectly handles specific file paths while processing web content. Users are protected by updating their devices to the latest software versions.
Technical details
A path handling vulnerability exists in Apple's WebKit-based components across Safari, iOS, iPadOS, and macOS. The issue stems from insufficient validation of file or resource paths during the processing of web content. An attacker can exploit this by tricking a user into visiting a maliciously crafted website, which could then bypass intended restrictions to access sensitive data. Apple addressed the root cause by implementing improved path validation logic. The fix is available in Safari 26.5.2, iOS/iPadOS 26.5.2, and macOS Tahoe 26.5.2.
Affected products
- Apple Safari < 26.5.2
- Apple iOS and iPadOS < 26.5.2
- Apple macOS Tahoe < 26.5.2
Timeline
- 2026-06-29: advisory: Initial advisory published by Apple.
- 2026-06-29: patched