Description
A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Opening a maliciously crafted webarchive file may lead to universal cross-site scripting.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Universal cross‑site scripting via malicious webarchive files in Apple browsers and OSes, enabling arbitrary JavaScript execution that can steal credentials and session data.
Action: Immediate Update
AI Analysis

Impact

A logic flaw in the state management of Apple’s web browsers and operating systems allows an attacker to trigger universal cross‑site scripting by providing a specially crafted webarchive file. This vulnerability can inject arbitrary JavaScript into any web page the victim visits, potentially exposing credentials, session data, or other sensitive information the site holds. The flaw does not directly allow remote code execution but enables the attacker to execute code in the context of the victim’s browser.

Affected Systems

The issue affects Apple Safari, iOS, iPadOS, macOS (Golden Gate), and visionOS. All versions prior to Safari 27, iOS 27, iPadOS 27, macOS Golden Gate 27, and visionOS 27.

Risk and Exploitability

Because the attack vector requires the victim to open a malicious webarchive file, an attacker could employ social‑engineering methods such as phishing emails or malicious downloads to deliver the file. Once opened, the exploit would execute in the browser context, providing broad access to the user’s browsing environment. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the potential impact of cross‑site scripting remains significant for affected users.

Generated by OpenCVE AI on September 15, 2026 at 08:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Safari, iOS, iPadOS, macOS, and visionOS to version 27 or later, which contains the state‑management fix
  • Ensure that automatic system and Safari updates are enabled so the device receives the security patch as soon as it is released
  • As a temporary measure, avoid opening or downloading the processing of webarchive formats if it is not required for normal use

Generated by OpenCVE AI on September 15, 2026 at 08:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Universal Cross‑Site Scripting via Malicious Webarchive in Apple Browsers and OSes
Weaknesses CWE-79

Tue, 15 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Opening a maliciously crafted webarchive file may lead to universal cross-site scripting.
References

Subscriptions

Apple Ios And Ipados Macos Safari Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:50:52.675Z

Reserved: 2026-09-08T16:43:41.873Z

Link: CVE-2026-86898

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:40.710

Modified: 2026-09-14T21:17:40.710

Link: CVE-2026-86898

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T08:30:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')