CVE-2026-64713

8.1

Apple · Safari, iOS, iPadOS, macOS, tvOS, visionOS, watchOS

A vulnerability in Apple software allows websites to determine if a user has previously visited a specific link, potentially compromising user privacy through unauthorized history tracking.

Executive summary

A privacy-related vulnerability in multiple Apple platforms allows malicious websites to track user browsing history, necessitating an immediate system update.

Vulnerability

This issue involves an improper implementation of browser history tracking checks, which allows an unauthenticated, remote attacker to determine if a user has visited specific web links through a malicious website.

Business impact

The ability for third-party websites to track user browsing history constitutes a significant privacy breach that can be leveraged for targeted phishing, social engineering, or behavioral profiling. While the CVSS score of 8.1 reflects a high severity due to the potential for unauthorized data exposure, the impact is primarily focused on user privacy and information gathering rather than direct system compromise. Organizations should treat this as a high priority to maintain the confidentiality of employee or user browsing habits.

Remediation

Immediate Action: Update all affected Apple devices to version 26.6 or later by navigating to the device system settings or software update menu.

Proactive Monitoring: Review web filtering logs for patterns of unusual traffic or suspicious redirect chains that may indicate attempts to leverage history tracking.

Compensating Controls: Utilize privacy-focused browser extensions that prevent tracking and fingerprinting, and ensure that cross-site tracking protection is enabled in Safari settings.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the broad impact across the Apple ecosystem, administrators should prioritize the deployment of the 26.6 update across all managed mobile and desktop devices. Failure to update leaves users vulnerable to persistent tracking by malicious entities, which can facilitate more complex follow-on attacks. Ensure that all devices are brought to the patched version as soon as possible to mitigate this privacy risk.

More Apple CVEs

Sources