Junglewise Threat Intelligence

CVE-2026-43735: Apple Safari and OS cross-origin data exfiltration

CVE-2026-43735 · Severity: info · CVSS 0 · Published 2026-06-29

Technologies: Apple Safari, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A vulnerability in Apple's Safari browser and operating systems could allow a malicious website to steal data from other websites you have open. This could lead to the unauthorized exposure of sensitive personal or account information. Users should update their Apple devices to the latest software versions to protect their data.

Technical details

A cross-origin data exfiltration vulnerability exists in Apple Safari and multiple Apple operating systems. The flaw allows a malicious website to bypass Same-Origin Policy (SOP) protections and exfiltrate data from other origins. The issue was caused by insufficient validation checks and has been addressed with improved logic in the affected components. An attacker would need to entice a user to visit a specially crafted website to trigger the exploit. The vulnerability is fixed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.

Affected products

  • Apple Safari before 26.5.2
  • Apple iOS and iPadOS before 26.5.2
  • Apple macOS Tahoe before 26.5.2

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: patched

References

Related threats