CVE-2026-20656
Analyzed Analyzed - Analysis Complete

Logic Flaw in Safari Allows Unauthorized Access to Browsing History

Vulnerability report for CVE-2026-20656, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-02-11

Last updated on: 2026-04-02

Assigner: Apple Inc.

Description

A logic issue was addressed with improved validation. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, macOS Tahoe 26.3. An app may be able to access a user's Safari history.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-02-11
Last Modified
2026-04-02
Generated
2026-07-26
AI Q&A
2026-02-12
EPSS Evaluated
2026-07-25
NVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
apple macos to 26.3 (exc)
apple ipados to 18.7.5 (exc)
apple iphone_os to 18.7.5 (exc)
apple safari to 26.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a logic issue that was addressed by improving validation in certain Apple operating systems and applications. Specifically, it could allow an app to access a user's Safari browsing history without proper authorization.

Detection Guidance

I don't know

Impact Analysis

The vulnerability could impact you by allowing an unauthorized app to access your Safari browsing history, potentially exposing your private browsing data and habits.

Compliance Impact

I don't know

Mitigation Strategies

To mitigate this vulnerability, update your devices and software to the fixed versions: iOS 18.7.5, iPadOS 18.7.5, Safari 26.3, and macOS Tahoe 26.3.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20656. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart