Executive brief
A privacy vulnerability in Apple's web browser and operating systems could allow malicious websites to determine if a user has previously visited specific links. This could lead to the tracking of a user's browsing history without their consent. The issue affects Safari and various Apple devices including iPhones, iPads, and Macs.
Technical details
A privacy vulnerability exists in Apple Safari and various Apple operating systems (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS) due to insufficient checks when handling link states. An attacker-controlled website can exploit this to determine if a user has visited a specific URL, effectively leaking browsing history. The issue was addressed by implementing improved checks to prevent history detection. The vulnerability is fixed in version 26.6 across all affected platforms.
Affected products
- Apple Safari < 26.6
- Apple iOS and iPadOS < 26.6
- Apple macOS < 26.6
- Apple tvOS < 26.6
- Apple visionOS < 26.6
- Apple watchOS < 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched