6.5mediumMedium

CVE-2026-64753

Apple Safari

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose sensitive user information.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is reachable over a network, without needing local access.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, no account is needed.
  • Beyond that, someone has to be persuaded to take an action first.

Scoring

CVSS
6.5 (v3.1)
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness
CWE-269
Assigned by
product-security@apple.com

Dates

Published
2026-09-14
Last modified
2026-09-15
Sources
NVD

Affected products

  • Apple Safari- 27.0
  • Apple Ipados- 27.0
  • Apple Iphone Os- 27.0
  • Apple Macos- 27.0
  • Apple Tvos- 27.0
  • Apple Visionos- 27.0
  • Apple Watchos- 27.0

As listed in the NVD configuration data. Not a statement about your estate.

References