CVE-2026-28861: Apple iPadOS
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access script message handlers intended for other origins.
Affected products
- Apple iPadOS: before 18.7.7 (fixed in 18.7.7); from 26.0, before 26.4 (fixed in 26.4)
- Apple iPhone OS: before 18.7.7 (fixed in 18.7.7); from 26.0, before 26.4 (fixed in 26.4)
- Apple macOS: before 26.4 (fixed in 26.4)
- Apple Safari: before 26.4 (fixed in 26.4)
- Apple visionOS: before 26.4 (fixed in 26.4)
Published 2026-03-25. Last modified 2026-07-15.