CVE-2026-65355
MEDIUMDescription
An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1. A website may be able to determine a user's IP address with Private Relay turned on.
Is your site exposed to CVE-2026-65355?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| apple | ipados |
| apple | ipados |
| apple | iphone_os |
| apple | iphone_os |
| apple | macos |
| apple | visionos |
References
Frequently Asked Questions
What is CVE-2026-65355? +
How severe is CVE-2026-65355? +
What products are affected by CVE-2026-65355? +
How do I check if I'm vulnerable to CVE-2026-65355? +
Related Vulnerabilities
Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie …
The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state …
External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated …
An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, …
An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CLI …
This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, …