Apple Safari Private Browsing Authentication Bypass Vulnerability

Vulnerability

A vulnerability exists in Apple Safari's private browsing feature, allowing tabs to be accessed without authentication. This issue affects Safari 18.2 on macOS Sequoia 15.2, watchOS 11.2, iOS 18.2, and iPadOS 18.2. The vulnerability arises from a logic flaw in state management, which could potentially be exploited to access private browsing data without proper authorization.

Impact

Exploitation of this vulnerability could lead to unauthorized access to private browsing tabs, bypassing authentication requirements.

Remediation

Users can update to Safari 18.2, macOS Sequoia 15.2, watchOS 11.2, iOS 18.2, or iPadOS 18.2 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.7
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.