Description
A cross-origin issue was addressed with improved tracking of security origins. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may disclose sensitive user information.
Severity (CVSS)
| Base score | 6.5 |
|---|---|
| Severity | Medium |
| Version | CVSS 3.1 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
| Provided by | CISA-ADP |
Weaknesses
- — Processing maliciously crafted web content may disclose sensitive user information
- CWE-346 — CWE-346 Origin Validation Error
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Safari | 0 to <26.5.2 |
| Apple | iOS and iPadOS | 0 to <26.5.2 |
| Apple | macOS | 0 to <26.5.2 |
References
Generated from the official CVE List on 30 Jun 2026 07:04 UTC.