The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvOS 26.1. A website may exfiltrate image data cross-origin.
The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Safari | Apple | * | 26.1 (excluding) |
| Ipados | Apple | * | 26.1 (excluding) |
| Iphone_os | Apple | * | 26.1 (excluding) |
| Tvos | Apple | * | 26.1 (excluding) |
| Visionos | Apple | * | 26.1 (excluding) |
| Watchos | Apple | * | 26.1 (excluding) |