Permissions Issue in Safari and Apple Operating Systems
CVE-2026-64728
6.5MEDIUM
What is CVE-2026-64728?
A permissions issue was identified that could allow maliciously crafted web content to circumvent the iframe sandboxing policy in Safari and other Apple operating systems. This vulnerability has been addressed with enhanced validation processes in the latest versions of Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS.
Affected Version(s)
iOS and iPadOS 0 < 26.6
macOS 0 < 26.6
Safari 0 < 26.6