Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A malicious website may be able to process restricted web content outside the sandbox.
Published: 2026-03-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sandbox Escape
Action: Apply Patch
AI Analysis

Impact

The flaw is a memory handling error that lets a malicious website process data that should be confined to the browser sandbox. The vulnerability is rooted in several classic memory errors such as buffer overreads, use‑after‑free, and buffer overflows, all of which are reflected in the assigned CWEs. If triggered, an attacker could read or alter content that is normally protected, enabling the site to access restricted information or influence sandboxed operations.

Affected Systems

Apple Safari on macOS, iOS, iPadOS, tvOS, visionOS and watchOS is affected whenever the software version is older than the 26.4 releases. The fix is delivered in Safari 26.4, iOS 26.4, iPadOS 26.4, macOS 26.4, tvOS 26.4, visionOS 26.4 and watchOS 26.4.

Risk and Exploitability

The CVSS score of 4.3 places this vulnerability in the low severity range, and the EPSS score of less than 1 % indicates that practical exploitation is unlikely at present. It is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is inferred to be remote, originating from a specially crafted web page that a user visits in Safari, exploiting the memory handling flaw to escape the sandbox. No active exploits or publicly available proof‑of‑concept code have been reported.

Generated by OpenCVE AI on March 31, 2026 at 06:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Apple software updates: Safari 26.4, iOS 26.4, iPadOS 26.4, macOS 26.4, tvOS 26.4, visionOS 26.4 and watchOS 26.4
  • Verify the current OS and Safari versions to confirm that the 26.4 releases are installed
  • If an update cannot be applied immediately, restrict browsing to trusted sites until the patch is installed

Generated by OpenCVE AI on March 31, 2026 at 06:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 31 Mar 2026 03:00:00 +0000

Type Values Removed Values Added
Title Safari and Apple OS Sandbox Escape via Improper Memory Handling webkitgtk: A malicious website may be able to process restricted web content outside the sandbox
Weaknesses CWE-120
References
Metrics threat_severity

None

threat_severity

Important


Thu, 26 Mar 2026 12:30:00 +0000

Type Values Removed Values Added
Title Safari and Apple OS Sandbox Escape via Improper Memory Handling

Wed, 25 Mar 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 25 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-416
CWE-787
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos

Wed, 25 Mar 2026 01:00:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A malicious website may be able to process restricted web content outside the sandbox.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:19:42.954Z

Reserved: 2026-03-03T16:36:03.972Z

Link: CVE-2026-28859

cve-icon Vulnrichment

Updated: 2026-03-25T19:29:26.282Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-25T01:17:10.023

Modified: 2026-03-25T21:54:26.793

Link: CVE-2026-28859

cve-icon Redhat

Severity : Important

Publid Date: 2026-03-28T20:00:00Z

Links: CVE-2026-28859 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-03-31T20:09:15Z