Description

A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access script message handlers intended for other origins.

INFO

Published Date :

2026-03-25T00:32:03.933Z

Last Modified :

2026-03-25T00:32:03.933Z

Source :

apple
AFFECTED PRODUCTS

The following products are affected by CVE-2026-28861 vulnerability.

No data.

REFERENCES

CVSS Vulnerability Scoring System