CVE-2026-65352: Input Validation
An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1. A website may be able to determine a user's IP address with Private Relay turned on.
Other sources
Audio. A logic issue was addressed with improved checks.
— Apple
Authentication Services. An information disclosure issue was addressed with improved state management.
— Apple
ImageIO. An integer overflow was addressed with improved input validation.
— Apple
ImageIO. The issue was addressed with improved checks.
— Apple
IOGPUFamily. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.6.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.6.2 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 26.6.1 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 26.6.1 - Upgrade
Upgrade
macOS Tahoeto a version that resolves this vulnerability.Fixed in 26.6.2 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 26.6.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-65355
- CVE-2026-65352
- CVE-2026-65339
- CVE-2026-65347
- CVE-2026-65346
- CVE-2026-64788
- CVE-2026-64736
- CVE-2026-65343
- CVE-2026-65349
- CVE-2026-65330
- CVE-2026-28935
- CVE-2026-64784
- CVE-2026-43795
- CVE-2026-65338
- CVE-2026-65341
- CVE-2026-64782
- CVE-2026-64781
- CVE-2026-65351
- CVE-2026-65340
- CVE-2026-65337
- CVE-2026-65336
- CVE-2026-65335
- CVE-2026-65333
- CVE-2026-65332
- CVE-2026-65331
- CVE-2026-64715
- CVE-2026-64780
- CVE-2026-65334
- CVE-2026-43794
- CVE-2026-64787
- CVE-2026-64778
- CVE-2026-64779
- CVE-2026-65391
- CVE-2026-65390
- CVE-2026-65329
Frequently Asked Questions
Which Apple platform versions contain the fix?
The issue is fixed in iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 26.6.1.
What does exploitation require according to the CVSS vector?
The vector indicates network-reachable exploitation with low attack complexity, no privileges required, and user interaction required. The stated impact is limited to confidentiality.
Are users of Private Relay potentially exposed?
Yes. The advisory states that a website may be able to determine a user's IP address even when Private Relay is turned on.