ZeroHour

CVE-2026-64753

mass

Permissions Flaw in Apple Safari and iOS/macOS Lets Web Content Leak User Data

CVSS 3.1
6.5 medium
EPSS
Published
()
Modified
AI analysis

CVE-2026-64753 is an improper privilege management (permissions) vulnerability in Apple's browser and operating system software that Apple fixed by removing the vulnerable code. It is triggered when a device processes maliciously crafted web content — typically a user visiting an attacker-controlled webpage — requiring user interaction but no privileges or attacker access to the device. Successful exploitation can disclose sensitive user information, reflected in a CVSS 3.1 base score of 6.5 (network vector, low attack complexity, high confidentiality impact, no integrity or availability impact). The flaw affects Safari and Apple's full OS lineup before the version 27 release wave — iOS, iPadOS, macOS Golden Gate, tvOS, visionOS, and watchOS — which shipped as part of a broad Apple update addressing 273 vulnerabilities. No public proof of concept is known, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been confirmed.

What to do: Update all Apple devices and browsers to the fixed releases: Safari 27, iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27, prioritizing iPhones and Macs used for web browsing. Because exploitation requires a user to load malicious web content, advise users to avoid untrusted links until patched. IT admins should verify update compliance across managed device fleets and monitor for post-update browsing anomalies indicating possible information disclosure.

Affected
Apple Safariversions prior to Safari 27
Apple iOSversions prior to iOS 27
Apple iPadOSversions prior to iPadOS 27
Apple macOS Golden Gateversions prior to macOS Golden Gate 27
Apple tvOSversions prior to tvOS 27
Apple visionOSversions prior to visionOS 27
Apple watchOSversions prior to watchOS 27
Estimated exposure
masslikely >1 billion users/devices potentially exposed before patching — Safari is the default browser across Apple's installed base, which the company has publicly sized at over 2 billion active devices worldwide, so the majority of unpatched iPhones, iPads, Macs, and other Apple devices were plausibly exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose sensitive user information.

Vendors
apple
Products
safari, ipados, iphone os, macos, tvos, visionos, watchos
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple's coordinated rollout patches 273 unique vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS and Safari, including remote code execution flaws.

Apple shipped one of its largest coordinated security updates on September 14, 2026, fixing 273 unique CVEs across iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27 and Xcode 27. Highlights include CVE-2026-65414, a Bluetooth out-of-bounds write enabling remote code execution, and CVE-2026-84607, an AVEVideoEncoder race condition granting kernel privileges to sandboxed apps. macOS Golden Gate 27 covers the broadest set with 210 CVEs, and Apple states none of the flaws were exploited in the wild.