5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Description
This issue was addressed through improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, Safari 26.3, macOS Tahoe 26.3, visionOS 26.3. A website may be able to track users through Safari web extensions.
Basic Information
ID
CVE-2026-20676
Source
apple
Published
Feb 11, 2026 at 22:58
Modified
Feb 17, 2026 at 15:23
Affected Product
Vendor
Apple
Product
Safari
Version
unspecified
Affected Versions
Apple Safari unspecified
Apple macOS unspecified
Apple visionOS unspecified
Apple iOS and iPadOS unspecified
Apple macOS unspecified
Apple visionOS unspecified
Apple iOS and iPadOS unspecified