Data Leakage Vulnerability in Apple iOS and macOS Products
CVE-2026-64778

6.5MEDIUM

Key Information:

Vendor

Apple

Vendor
CVE Published:
17 August 2026

What is CVE-2026-64778?

CVE-2026-64778 is a data leakage vulnerability affecting Apple's iOS and macOS products, including Safari. This vulnerability could allow malicious websites to access and leak sensitive user data, posing a significant risk to organizations and individuals relying on Apple’s ecosystem for secure communication and operations. The issue arises from inadequate data checks when navigating to compromise sites, which could lead to unauthorized disclosure of private information. Apple has addressed this flaw in updates for Safari, iOS, iPadOS, and macOS, underscoring the importance of periodic software updates for maintaining security.

Potential impact of CVE-2026-64778

  1. Data Breach Risk: The vulnerability can facilitate the unauthorized sharing of sensitive data, increasing the likelihood of data breaches that could expose personal or confidential information.

  2. Reputation Damage: Organizations affected by this vulnerability may face serious reputational harm if user data is leaked, leading to a loss of trust among customers and stakeholders.

  3. Compliance Violations: Companies subject to data protection regulations may face legal and financial repercussions due to non-compliance from the unauthorized disclosure of protected data, resulting from this vulnerability.

Affected Version(s)

iOS and iPadOS 0 < 18.7.10

iOS and iPadOS 0 < 26.6.1

macOS 0 < 26.6.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.