CVE-2026-20691 PUBLISHED

Assigner: apple
Reserved: 11.11.2025 Published: 25.03.2026 Updated: 25.03.2026

An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A maliciously crafted webpage may be able to fingerprint the user.

Product Status

Vendor Apple
Product Safari
Versions
  • affected from 0 to 26.4 (excl.)
Vendor Apple
Product iOS and iPadOS
Versions
  • affected from 0 to 26.4 (excl.)
Vendor Apple
Product macOS
Versions
  • affected from 0 to 26.4 (excl.)
Vendor Apple
Product visionOS
Versions
  • affected from 0 to 26.4 (excl.)
Vendor Apple
Product watchOS
Versions
  • affected from 0 to 26.4 (excl.)

References

Problem Types

  • A maliciously crafted webpage may be able to fingerprint the user