Logic Issue in Safari and Apple Products Leading to Improper Origin Access
CVE-2026-28861
4.3MEDIUM
Key Information:
- Vendor
Apple
- Vendor
- CVE Published:
- 25 March 2026
What is CVE-2026-28861?
A logic issue in Safari and various Apple products has been identified, impacting state management and allowing malicious websites to potentially access script message handlers that are intended for different origins. This vulnerability highlights the necessity of robust security measures, as it could enable unauthorized actions or data breaches through deceptive websites. Apple has addressed this issue in the latest updates across multiple platforms, reinforcing their commitment to user security.
Affected Version(s)
iOS and iPadOS 0 < 18.7.7
iOS and iPadOS 0 < 26.4
macOS 0 < 26.4