SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-65355

MEDIUM · CVSS 4.3 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An information disclosure vulnerability allows websites to potentially determine a user's IP address even when Private Relay is enabled on affected Apple devices. This could lead to privacy concerns for users relying on this feature for anonymity. Organizations and individuals using iOS, iPadOS, macOS, or visionOS should prioritize updating to the latest versions to mitigate this risk.

CVE
CVE-2026-65355
Severity
MEDIUM
CVSS
4.3
EPSS
0.26%

Original NVD Description

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1. A website may be able to determine a user's IP address with Private Relay turned on.

Related CVEs

Other vulnerabilities affecting the same vendor(s)