CVE-2026-28859 PUBLISHED

Assigner: apple
Reserved: 03.03.2026 Published: 25.03.2026 Updated: 25.03.2026

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A malicious website may be able to process restricted web content outside the sandbox.

Product Status

Vendor Apple
Product Safari
Versions
  • affected from 0 to 26.4 (excl.)
Vendor Apple
Product iOS and iPadOS
Versions
  • affected from 0 to 26.4 (excl.)
Vendor Apple
Product macOS
Versions
  • affected from 0 to 26.4 (excl.)
Vendor Apple
Product tvOS
Versions
  • affected from 0 to 26.4 (excl.)
Vendor Apple
Product visionOS
Versions
  • affected from 0 to 26.4 (excl.)
Vendor Apple
Product watchOS
Versions
  • affected from 0 to 26.4 (excl.)

References

Problem Types

  • A malicious website may be able to process restricted web content outside the sandbox