6.5mediumMedium
CVE-2026-64753
Apple Safari
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose sensitive user information.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, no account is needed.
- Beyond that, someone has to be persuaded to take an action first.
Scoring
- CVSS
- 6.5 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N- Weakness
- CWE-269
- Assigned by
- product-security@apple.com
Dates
- Published
- 2026-09-14
- Last modified
- 2026-09-15
- Sources
- NVD
Affected products
- Apple Safari- 27.0
- Apple Ipados- 27.0
- Apple Iphone Os- 27.0
- Apple Macos- 27.0
- Apple Tvos- 27.0
- Apple Visionos- 27.0
- Apple Watchos- 27.0
As listed in the NVD configuration data. Not a statement about your estate.