Executive brief
An authorization issue in Apple Safari and macOS Tahoe could allow a malicious application to access sensitive user data. This vulnerability stems from how the system manages internal states during authorization requests. If exploited, a user's private information could be exposed to unauthorized apps running on the device.
Technical details
An authorization vulnerability exists in Apple Safari and macOS Tahoe prior to version 26.6. The flaw is rooted in improper state management during authorization processes. A local malicious application could exploit this weakness to bypass intended access controls and retrieve sensitive user information. Apple addressed the issue by improving state management logic in the affected components. An attacker would require the ability to run an application on the target system to exploit this vulnerability.
Affected products
- Apple Safari before 26.6
- Apple macOS Tahoe before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory
- 2026-07-27: patched