Memory Handling Vulnerability in Safari and Apple Devices
CVE-2026-28859

4.3MEDIUM

Key Information:

Vendor

Apple

Vendor
CVE Published:
25 March 2026

What is CVE-2026-28859?

A vulnerability exists in Safari and related Apple products that involves inadequate memory management. This flaw could permit malicious websites to bypass the browser's sandbox protections, enabling them to access restricted web content. This security risk has been mitigated in the updates of Safari 26.4 and various operating systems including iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

iOS and iPadOS 0 < 26.4

macOS 0 < 26.4

Safari 0 < 26.4

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.