Junglewise Threat Intelligence

CVE-2026-64728: Apple Safari and OSs iframe sandboxing bypass

CVE-2026-64728 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS, Apple Safari, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability in Apple's web browser and operating systems could allow malicious websites to bypass security restrictions designed to isolate web content. This could allow a malicious site to perform actions or access information it should not have permission to reach. Users should update their Apple devices to the latest software versions to ensure these protections are enforced correctly.

Technical details

A permissions issue was identified in WebKit-based components where improper validation allowed maliciously crafted web content to bypass iframe sandboxing policies. By exploiting this flaw, an attacker-controlled website could potentially escape the restricted environment of an iframe to perform unauthorized actions or access data across origins. The issue was addressed through improved validation of sandboxing attributes. The vulnerability affects Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS, and is fixed in version 26.6 of these platforms.

Affected products

  • Apple Safari before 26.6
  • Apple iOS and iPadOS before 26.6
  • Apple macOS Tahoe before 26.6
  • Apple tvOS before 26.6
  • Apple visionOS before 26.6
  • Apple watchOS before 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: advisory

References

Related threats