Apple visionOS
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*
A vulnerability in WebKit, the engine used by Safari, allows malicious websites to exfiltrate image data from the user's device to a third party, bypassing cross-origin restrictions. This issue affects multiple Apple platforms, including iOS, iPadOS, watchOS, tvOS, and visionOS, all in version 26.1. The vulnerability arises from improper handling of caches, which can be exploited to access and transfer image data without user consent.
Exploitation of this vulnerability could lead to unauthorized access and transfer of image data from the user's device to a third party, violating privacy and data security.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.