Apple WebKit Cross-Origin Data Exfiltration Vulnerability

Vulnerability

A vulnerability in WebKit, the engine used by Safari, allows malicious websites to exfiltrate image data from the user's device to a third party, bypassing cross-origin restrictions. This issue affects multiple Apple platforms, including iOS, iPadOS, watchOS, tvOS, and visionOS, all in version 26.1. The vulnerability arises from improper handling of caches, which can be exploited to access and transfer image data without user consent.

Impact

Exploitation of this vulnerability could lead to unauthorized access and transfer of image data from the user's device to a third party, violating privacy and data security.

Added: Nov 4, 2025, 3:12 AM
Updated: Nov 4, 2025, 3:12 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.