cbcvebase.
CVE-2026-28861
published 2026-03-25

CVE-2026-28861: A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS…

medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access script message handlers intended for other origins.

Affected

12 ranges
VendorProductVersion rangeFixed in
appleios_and_ipados< 18.7.718.7.7
appleios_and_ipados< 26.426.4
appleipados< 18.7.718.7.7
appleipados>= 26.0 < 26.426.4
appleiphone_os< 18.7.718.7.7
appleiphone_os>= 26.0 < 26.426.4
applemacos< 26.426.4
applesafari< 26.426.4
applevisionos< 26.426.4
debianwebkit2gtk< webkit2gtk 2.52.1-1 (sid)webkit2gtk 2.52.1-1 (sid)
debianwpewebkit< webkit2gtk 2.52.1-1 (sid)webkit2gtk 2.52.1-1 (sid)
ubuntuwebkit2gtk

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
osv4.3MEDIUM