This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to silently hijack clipboard data.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Safari | Apple | * | 26.5.2 (excluding) |
| Ipados | Apple | * | 26.5.2 (excluding) |
| Iphone_os | Apple | * | 26.5.2 (excluding) |
| Macos | Apple | 26.0 (including) | 26.5.2 (excluding) |
| Red Hat Enterprise Linux 8 | RedHat | webkit2gtk3-0:2.52.5-1.el8_10 | * |
| Red Hat Enterprise Linux 9 | RedHat | webkit2gtk3-0:2.52.5-1.el9_8 | * |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | RedHat | webkit2gtk3-0:2.52.5-1.el9_4 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | webkit2gtk3-0:2.52.5-1.el9_6 | * |