Executive brief
A security vulnerability in Apple operating systems and the Safari browser could allow a malicious application to bypass standard security boundaries. Specifically, an app could read sensitive files that it should not have access to, potentially leading to the exposure of private user data. This issue affects iPhones, iPads, Macs, and other Apple devices running older software versions.
Technical details
An access issue was identified in multiple Apple operating systems where improved access restrictions were required to maintain sandbox integrity. The vulnerability allows a locally installed application to bypass sandbox constraints and read files outside of its designated directory. This could lead to unauthorized access to sensitive system or user files. The issue was addressed through improved access restrictions in the affected components. Patches are available in Safari 26.6, iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Affected products
- Apple Safari before 26.6
- Apple iOS and iPadOS before 26.6
- Apple macOS Tahoe before 26.6
- Apple tvOS before 26.6
- Apple visionOS before 26.6
- Apple watchOS before 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: disclosed
- 2026-07-27: patched