EIP-2026-104576

PRE-CVE

Apple Mac OS X + Safari - Local Javascript Quarantine Bypass

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104576. PoCs published by Filippo Cavallarin.

AI-analyzed exploit summary This exploit demonstrates a DOM-based XSS vulnerability in Mac OS X's rhtmlPlayer.html, allowing arbitrary JavaScript execution outside the quarantine sandbox. The PoC leverages .webloc files and a data URI to bypass Apple's Quarantine mechanism.

Description

Apple Mac OS X + Safari - Local Javascript Quarantine Bypass

Exploits (1)

exploitdb WORKING POC
by Filippo Cavallarin · textlocalosx
https://www.exploit-db.com/exploits/42948

This exploit demonstrates a DOM-based XSS vulnerability in Mac OS X's rhtmlPlayer.html, allowing arbitrary JavaScript execution outside the quarantine sandbox. The PoC leverages .webloc files and a data URI to bypass Apple's Quarantine mechanism.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: Mac OS X 10.10, 10.11, 10.12
No auth needed
Prerequisites: Victim must open a crafted .webloc file · Attacker must deliver the file via an archive preserving extended attributes
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026