CVE-2026-43721
published 2026-06-29CVE-2026-43721: This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.24%
15.5th percentile
This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may be able to silently hijack clipboard data.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 26.5.2 | 26.5.2 |
| apple | ipados | < 26.5.2 | 26.5.2 |
| apple | iphone_os | < 26.5.2 | 26.5.2 |
| apple | macos | < 26.5.2 | 26.5.2 |
| apple | macos | >= 26.0 < 26.5.2 | 26.5.2 |
| apple | safari | < 26.5.2 | 26.5.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Website Remote Code Execution
vuldb·2026-06-30
CVE-2026-43721 [CRITICAL] Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Website Remote Code Execution
A vulnerability was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. It has been rated as critical. This affects an unknown function of the component Website Handler. Performing a manipulation results in Remote Code Execution.
This vulnerability is known as CVE-2026-43721. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
GHSA
This issue was addressed through improved state management.
ghsa_unreviewed·2026-06-29
CVE-2026-43721 [HIGH] CWE-732 This issue was addressed through improved state management.
This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may be able to silently hijack clipboard data.
No detection rules found.
No public exploits indexed.
2026-06-29
Published