CVE-2026-43721
Modified
Modified - Updated After Analysis
Clipboard Data Hijacking in Safari and iOS
Vulnerability report for CVE-2026-43721, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-06-29
Last updated on: 2026-06-30
Assigner: Apple Inc.
Description
Description
This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may be able to silently hijack clipboard data.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | safari | to 26.5.2 (exc) |
| apple | ipados | to 26.5.2 (exc) |
| apple | iphone_os | to 26.5.2 (exc) |
| apple | macos | From 26.0 (inc) to 26.5.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |