AI analysis
CVE-2026-64753 is an improper privilege management (permissions) vulnerability in Apple's browser and operating system software that Apple fixed by removing the vulnerable code. It is triggered when a device processes maliciously crafted web content — typically a user visiting an attacker-controlled webpage — requiring user interaction but no privileges or attacker access to the device. Successful exploitation can disclose sensitive user information, reflected in a CVSS 3.1 base score of 6.5 (network vector, low attack complexity, high confidentiality impact, no integrity or availability impact). The flaw affects Safari and Apple's full OS lineup before the version 27 release wave — iOS, iPadOS, macOS Golden Gate, tvOS, visionOS, and watchOS — which shipped as part of a broad Apple update addressing 273 vulnerabilities. No public proof of concept is known, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been confirmed.
What to do: Update all Apple devices and browsers to the fixed releases: Safari 27, iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27, prioritizing iPhones and Macs used for web browsing. Because exploitation requires a user to load malicious web content, advise users to avoid untrusted links until patched. IT admins should verify update compliance across managed device fleets and monitor for post-update browsing anomalies indicating possible information disclosure.
Affected
| Apple Safari | versions prior to Safari 27 |
| Apple iOS | versions prior to iOS 27 |
| Apple iPadOS | versions prior to iPadOS 27 |
| Apple macOS Golden Gate | versions prior to macOS Golden Gate 27 |
| Apple tvOS | versions prior to tvOS 27 |
| Apple visionOS | versions prior to visionOS 27 |
| Apple watchOS | versions prior to watchOS 27 |
Estimated exposure
masslikely >1 billion users/devices potentially exposed before patching — Safari is the default browser across Apple's installed base, which the company has publicly sized at over 2 billion active devices worldwide, so the majority of unpatched iPhones, iPads, Macs, and other Apple devices were plausibly exposed…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose sensitive user information.