Executive brief
Safari is Apple's web browser used across devices and computers to view websites and web content. A permissions issue in Safari could allow maliciously crafted web pages to disclose sensitive user information to an attacker without proper authorization. This affects Safari on iPhones, iPads, and Mac computers.
Technical details
CVE-2026-64753 is a permissions issue in Safari's handling of sensitive user data access. The vulnerability was addressed by removing the vulnerable code rather than patching it. An attacker can craft malicious web content that, when processed by Safari, bypasses permission checks to access and disclose sensitive information. The attack vector is network-based through web content delivery. Apple has issued patches in Safari 27, iOS 27, iPadOS 27, and macOS Golden Gate 27 (released September 14, 2026).
Affected products
- Apple Safari before 27
- Apple iOS before 27
- Apple iPadOS before 27
- Apple macOS Golden Gate before 27
Timeline
- 2026-09-14: disclosed: CVE-2026-64753 published; patches released
- 2026-09-14: patched: Fixed in Safari 27, iOS 27, iPadOS 27, macOS Golden Gate 27