
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20656 is a logic issue in Apple's Safari browser that allows a local app to access a user's Safari browsing history without proper authorization. It affects Safari versions before 26.3, iOS and iPadOS versions before 18.7.5, and macOS Tahoe versions before 26.3. The vulnerability was disclosed and patched on February 11, 2026. It carries a CVSS v3.1 base score of 3.3 (Low), reflecting its local attack vector and limited confidentiality impact (Apple Safari Advisory, Apple iOS/iPadOS Advisory, Apple macOS Advisory).
The vulnerability is classified as CWE-285 (Improper Authorization), stemming from a logic flaw in how Safari validates access to its browsing history data. An app running on the same device with low-level privileges can bypass the intended authorization checks and read the user's Safari history without user consent or elevated permissions. Apple addressed the issue with improved validation logic in the affected components. The vulnerability was discovered and reported by Mickey Jin (@patch1t) (Apple Safari Advisory, Apple macOS Advisory).
Successful exploitation allows a malicious app installed on the device to read the victim's Safari browsing history, exposing potentially sensitive information about the user's online activity, visited sites, and behavioral patterns. The impact is limited to confidentiality — there is no integrity or availability impact. While the vulnerability does not enable remote code execution or lateral movement, the exposed browsing history could be leveraged for targeted phishing, profiling, or surveillance purposes (Apple Safari Advisory, Apple iOS/iPadOS Advisory).
Apple has released patches addressing this vulnerability. Users should update to Safari 26.3, iOS 18.7.5, iPadOS 18.7.5, or macOS Tahoe 26.3 or later. No configuration-based workarounds have been published; updating to the patched versions is the only recommended remediation. Users should also exercise caution when installing third-party apps from untrusted sources, as exploitation requires a malicious app to be present on the device (Apple Safari Advisory, Apple iOS/iPadOS Advisory, Apple macOS Advisory).
The vulnerability was noted in standard security community channels including SANS Internet Storm Center and Seclists Full Disclosure mailing list shortly after Apple's February 11, 2026 disclosure. No significant independent researcher commentary or notable media coverage beyond routine patch reporting has been identified for this specific CVE, consistent with its low severity rating.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."