The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvOS 26.1. A website may exfiltrate image data cross-origin.
https://support.apple.com/en-us/125640
https://support.apple.com/en-us/125639
https://support.apple.com/en-us/125638