CVE-2026-65352
MEDIUMDescription
An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1. A website may be able to determine a user's IP address with Private Relay turned on.
Is your site exposed to CVE-2026-65352?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| apple | ipados |
| apple | iphone_os |
| apple | macos |
| apple | visionos |
References
Frequently Asked Questions
What is CVE-2026-65352? +
How severe is CVE-2026-65352? +
What products are affected by CVE-2026-65352? +
How do I check if I'm vulnerable to CVE-2026-65352? +
Related Vulnerabilities
Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie …
The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state …
External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated …
An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, …
An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CLI …
An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, …