CVE-2026-28871 PUBLISHED

Assigner: apple
Reserved: 03.03.2026 Published: 25.03.2026 Updated: 25.03.2026

A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4. Visiting a maliciously crafted website may lead to a cross-site scripting attack.

Product Status

Vendor Apple
Product Safari
Versions
  • affected from 0 to 26.4 (excl.)
Vendor Apple
Product iOS and iPadOS
Versions
  • affected from 0 to 18.7.7 (excl.)
  • affected from 0 to 26.4 (excl.)
Vendor Apple
Product macOS
Versions
  • affected from 0 to 26.4 (excl.)

References

Problem Types

  • Visiting a maliciously crafted website may lead to a cross-site scripting attack