CVE-2026-28871: Apple iPadOS

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4. Visiting a maliciously crafted website may lead to a cross-site scripting attack.

Affected products

  • Apple iPadOS: before 18.7.7 (fixed in 18.7.7); from 26.0, before 26.4 (fixed in 26.4)
  • Apple iPhone OS: before 18.7.7 (fixed in 18.7.7); from 26.0, before 26.4 (fixed in 26.4)
  • Apple macOS: before 26.4 (fixed in 26.4)
  • Apple Safari: before 26.4 (fixed in 26.4)

Published 2026-03-25. Last modified 2026-06-17.