Junglewise Threat Intelligence

CVE-2026-64753: Apple Safari permissions information disclosure vulnerability

CVE-2026-64753 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS, Apple Safari, Apple macOS Golden Gate, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Safari is Apple's web browser used across devices and computers to view websites and web content. A permissions issue in Safari could allow maliciously crafted web pages to disclose sensitive user information to an attacker without proper authorization. This affects Safari on iPhones, iPads, and Mac computers.

Technical details

CVE-2026-64753 is a permissions issue in Safari's handling of sensitive user data access. The vulnerability was addressed by removing the vulnerable code rather than patching it. An attacker can craft malicious web content that, when processed by Safari, bypasses permission checks to access and disclose sensitive information. The attack vector is network-based through web content delivery. Apple has issued patches in Safari 27, iOS 27, iPadOS 27, and macOS Golden Gate 27 (released September 14, 2026).

Affected products

  • Apple Safari before 27
  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-64753 published; patches released
  • 2026-09-14: patched: Fixed in Safari 27, iOS 27, iPadOS 27, macOS Golden Gate 27

References

Related threats