This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to silently hijack clipboard data.
References
| Link | Resource |
|---|---|
| https://support.apple.com/en-us/127594 | Vendor Advisory |
| https://support.apple.com/en-us/127595 | Vendor Advisory |
| https://support.apple.com/en-us/127685 | Vendor Advisory |
| https://support.apple.com/en-us/128068 | |
| https://support.apple.com/en-us/128069 | |
| https://support.apple.com/en-us/128070 |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-06-29 20:17
Updated : 2026-07-27 21:16
NVD link : CVE-2026-43721
Mitre link : CVE-2026-43721
CVE.ORG link : CVE-2026-43721
JSON object : View
Products Affected
apple
- iphone_os
- ipados
- safari
- macos
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
