EIP-2026-104576
PRE-CVEApple Mac OS X + Safari - Local Javascript Quarantine Bypass
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104576. PoCs published by Filippo Cavallarin.
AI-analyzed exploit summary This exploit demonstrates a DOM-based XSS vulnerability in Mac OS X's rhtmlPlayer.html, allowing arbitrary JavaScript execution outside the quarantine sandbox. The PoC leverages .webloc files and a data URI to bypass Apple's Quarantine mechanism.
Description
Apple Mac OS X + Safari - Local Javascript Quarantine Bypass
Exploits (1)
exploitdb
WORKING POC
by Filippo Cavallarin · textlocalosx
https://www.exploit-db.com/exploits/42948
This exploit demonstrates a DOM-based XSS vulnerability in Mac OS X's rhtmlPlayer.html, allowing arbitrary JavaScript execution outside the quarantine sandbox. The PoC leverages .webloc files and a data URI to bypass Apple's Quarantine mechanism.
Classification
Working Poc 95%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target:
Mac OS X 10.10, 10.11, 10.12
No auth needed
Prerequisites:
Victim must open a crafted .webloc file · Attacker must deliver the file via an archive preserving extended attributes
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026