UI Spoofing Vulnerability Affecting Apple Safari and Related Products
CVE-2026-64730

6.5MEDIUM

Key Information:

Vendor

Apple

Vendor
CVE Published:
27 July 2026

What is CVE-2026-64730?

A UI spoofing vulnerability exists in Apple Safari and associated platforms due to improper handling of framed content. This can allow an attacker to display deceptive interfaces that mislead users, potentially leading to user actions that compromise sensitive information. The issue has been resolved with updates in Safari 26.6, ensuring users are protected from malicious content that could exploit this vulnerability.

Affected Version(s)

iOS and iPadOS 0 < 26.6

macOS 0 < 26.6

Safari 0 < 26.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.