A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Opening a maliciously crafted webarchive file may lead to universal cross-site scripting.
| Vendor | Product | Versions |
|---|---|---|
| apple | safari | 0, 0, 0, 0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apple | macos | cert_advisory | 90% |
| apple | ipados | cert_advisory | 90% |
| apple | safari | cert_advisory | 90% |
| apple | ios | cert_advisory | 90% |
| open source | webkitgtk | cert_advisory | 90% |
Loading…