Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2950 articles · 106553 vulns · 38/41 feeds (7d)
← Back to list
4.3
CVE-2026-28861EXPLOITEDPATCHED
apple · safari

A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious web

Description

A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access script message handlers intended for other origins.

Affected Products

VendorProductVersions
applesafari< 26.4, < 18.7.7, < 26.4, < 18.7.7, < 26.4, < 26.4, < 26.4

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
applesafaricert_advisory90%

References

  • https://support.apple.com/en-us/126792(Release Notes, Vendor Advisory)
  • https://support.apple.com/en-us/126793(Release Notes, Vendor Advisory)
  • https://support.apple.com/en-us/126794(Release Notes, Vendor Advisory)
  • https://support.apple.com/en-us/126799(Release Notes, Vendor Advisory)
  • https://support.apple.com/en-us/126800(Release Notes, Vendor Advisory)

Related News (3 articles)

Tier C
oss-security4d ago
WebKitGTK and WPE WebKit Security Advisory WSA-2026-0002
→ No new info (linked only)
Tier B
BSI Advisories7d ago
[NEU] [hoch] Apple Safari: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR7d ago
Multiples vulnérabilités dans les produits Apple (25 mars 2026)
→ No new info (linked only)
CVSS 3.14.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
18.7.726.4
PublishedMar 25, 2026
Last enriched5d ago
Tags
macosprivilege escalationdenial of serviceinformation disclosuresecurity bypasscross-site scriptingios
Trending Score29
Source articles3
Independent3
Info Completeness7/14
Missing: epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-28871EXP
CVE-2026-28871: A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS
Trending: 39
HIGHCVE-2026-20700EXPKEV
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memo
Trending: 37
MEDIUMCVE-2026-28890
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpected system termination.
Trending: 24
HIGHCVE-2023-43010
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Pr
Trending: 24
HIGHCVE-2026-20652
The issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.3, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3, Safari 26.3. A remote attacker ma
Trending: 24

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Mar 25, 2026
Actively Exploited
Mar 26, 2026
Exploit Available
Mar 26, 2026
Patch Available
Mar 26, 2026
Discovered by ZDM
Mar 26, 2026