The issue was addressed with improved checks. This issue...
High severity
Unreviewed
Published
Nov 4, 2025
to the GitHub Advisory Database
•
Updated Dec 17, 2025
Description
Published by the National Vulnerability Database
Nov 4, 2025
Published to the GitHub Advisory Database
Nov 4, 2025
Last updated
Dec 17, 2025
The issue was addressed with improved checks. This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvOS 26.1. A malicious website may exfiltrate data cross-origin.
References