2026-07-27 20:13CVE-2026-64730apple
PUBLISHED5.2

The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Visiting a website that frames malicious content may lead to UI spoofing.

Problem type

  • Visiting a website that frames malicious content may lead to UI spoofing

Affected products

Apple

Safari

< 26.6 - AFFECTED

iOS and iPadOS

< 26.6 - AFFECTED

macOS

< 26.6 - AFFECTED

tvOS

< 26.6 - AFFECTED

visionOS

< 26.6 - AFFECTED

watchOS

< 26.6 - AFFECTED

References

GitHub Security Advisories

GHSA-4mhm-fvhw-2xxw

The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS...

https://github.com/advisories/GHSA-4mhm-fvhw-2xxw

The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Visiting a website that frames malicious content may lead to UI spoofing.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-64730
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-64730",
    "assignerOrgId": "286789f9-fbc2-4510-9f9a-43facdede74c",
    "assignerShortName": "apple",
    "dateUpdated": "2026-07-28T14:04:05.762Z",
    "dateReserved": "2026-07-20T18:09:47.193Z",
    "datePublished": "2026-07-27T20:13:50.343Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "286789f9-fbc2-4510-9f9a-43facdede74c",
        "shortName": "apple",
        "dateUpdated": "2026-07-27T20:13:50.343Z"
      },
      "descriptions": [
        {
          "lang": "en",
          "value": "The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Visiting a website that frames malicious content may lead to UI spoofing."
        }
      ],
      "affected": [
        {
          "vendor": "Apple",
          "product": "Safari",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "iOS and iPadOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "macOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "tvOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "visionOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "watchOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Visiting a website that frames malicious content may lead to UI spoofing"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066"
        },
        {
          "url": "https://support.apple.com/en-us/128067"
        },
        {
          "url": "https://support.apple.com/en-us/128068"
        },
        {
          "url": "https://support.apple.com/en-us/128069"
        },
        {
          "url": "https://support.apple.com/en-us/128070"
        },
        {
          "url": "https://support.apple.com/en-us/128073"
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP",
          "dateUpdated": "2026-07-28T14:04:05.762Z"
        },
        "title": "CISA ADP Vulnrichment",
        "problemTypes": [
          {
            "descriptions": [
              {
                "lang": "en",
                "description": "CWE-451 User Interface (UI) Misrepresentation of Critical Information",
                "cweId": "CWE-451",
                "type": "CWE"
              }
            ]
          }
        ],
        "metrics": [
          {
            "cvssV3_1": {
              "version": "3.1",
              "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
              "attackVector": "NETWORK",
              "attackComplexity": "LOW",
              "privilegesRequired": "NONE",
              "userInteraction": "REQUIRED",
              "scope": "UNCHANGED",
              "confidentialityImpact": "NONE",
              "integrityImpact": "HIGH",
              "availabilityImpact": "NONE",
              "baseScore": 6.5,
              "baseSeverity": "MEDIUM"
            }
          },
          {}
        ]
      }
    ]
  }
}