Description
A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4. Visiting a maliciously crafted website may lead to a cross-site scripting attack.
Published: 2026-03-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting via Malicious Website
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a logic issue that allows a malicious website to execute arbitrary scripting code within the browsing context. Because the flaw was not properly checked, a site can cause the browser to run any JavaScript entered by the attacker. This results in a classic cross‑site scripting attack that can compromise user data, session credentials, or execute further malicious payloads. The weakness is classified as CWE‑79.

Affected Systems

Affected products are Apple Safari on macOS, iOS, and iPadOS. The flaw is present in Safari versions prior to 26.4, iOS and iPadOS prior to 18.7.7 (and 26.4), and macOS Tahoe prior to 26.4. Users running any earlier builds are potentially vulnerable.

Risk and Exploitability

The CVSS base score is 4.3, indicating low‑to‑moderate severity, and the EPSS score is less than 1 %, suggesting a low probability of exploitation in the wild. Apple has not listed this vulnerability in the KEV catalog. The attack likely requires a user to visit a crafted site, so the vector is remote web-based. The overall risk is modest, but any reachable data could be exposed if the site is visited.

Generated by OpenCVE AI on March 30, 2026 at 13:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Safari to version 26.4 or later
  • Update iOS to 18.7.7 or later
  • Update iPadOS to 18.7.7 or later
  • Update macOS to Tahoe 26.4 or later
  • If immediate update is not possible, enforce strict content‑blocking policies and limit JavaScript execution via device management

Generated by OpenCVE AI on March 30, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 31 Mar 2026 03:00:00 +0000

Type Values Removed Values Added
Title Apple Browsers and OS Vulnerable to Cross‑Site Scripting from Malicious Websites webkitgtk: Visiting a maliciously crafted website may lead to a cross-site scripting attack
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 30 Mar 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Sun, 29 Mar 2026 20:45:00 +0000

Type Values Removed Values Added
Title Apple Browsers and OS Vulnerable to Cross‑Site Scripting from Malicious Websites

Sat, 28 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Mar 2026 20:30:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Vulnerability in Safari and Apple Mobile Platforms
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Fri, 27 Mar 2026 09:30:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Vulnerability in Safari and Apple Mobile Platforms
Weaknesses CWE-79

Thu, 26 Mar 2026 12:30:00 +0000

Type Values Removed Values Added
Title Logic Issue Leading to Cross‑Site Scripting in Safari and macOS
Weaknesses CWE-79

Wed, 25 Mar 2026 22:00:00 +0000

Type Values Removed Values Added
Title Logic Issue Leading to Cross‑Site Scripting in Safari and macOS
Weaknesses CWE-79

Wed, 25 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari

Wed, 25 Mar 2026 01:00:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4. Visiting a maliciously crafted website may lead to a cross-site scripting attack.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Safari
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:07:54.461Z

Reserved: 2026-03-03T16:36:03.974Z

Link: CVE-2026-28871

cve-icon Vulnrichment

Updated: 2026-03-27T19:45:20.278Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-25T01:17:11.110

Modified: 2026-03-30T12:27:17.473

Link: CVE-2026-28871

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-03-28T20:00:00Z

Links: CVE-2026-28871 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-03-30T20:58:01Z

Weaknesses