CVE-2026-65355Medium· 4.3▾ SunlitAn information disclosure issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1. A website may be able to determine a …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
— → 4.3
none → medium
Last analysed / modified upstream
0.3%
An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1. A website may be able to determine a user's IP address with Private Relay turned on.
ipados < 18.7.10ipados >= 26.0, < 26.6.1iphone_os < 18.7.10iphone_os >= 26.0, < 26.6.1macos < 26.6.2visionos < 26.6.1Upgrade past the affected range:
ipados 26.6.1iphone_os 26.6.1macos 26.6.2visionos 26.6.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-65352Medium· 4.3An information disclosure issue was addressed with improved state management
CVE-2026-64781Medium· 4.3The issue was addressed with improved input validation
CVE-2026-65333Medium· 4.3This issue was addressed through improved state management
CVE-2026-65349Medium· 6.6An out-of-bounds read was addressed with improved input validation
CVE-2026-28935High· 7.5The issue was addressed with improved memory handling
CVE-2026-65343High· 7.5A use after free issue was addressed with improved memory management