Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1489 articles · 105580 vulns · 38/41 feeds (7d)
← Back to list
4.3
CVE-2026-28871EXPLOITED
apple · safari

CVE-2026-28871: A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS

Description

A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4. Visiting a maliciously crafted website may lead to a cross-site scripting attack.

Affected Products

VendorProductVersions
applesafari0, 0, 0, 0

References

  • https://support.apple.com/en-us/126792
  • https://support.apple.com/en-us/126793
  • https://support.apple.com/en-us/126794
  • https://support.apple.com/en-us/126800

Related News (3 articles)

Tier C
oss-security6h ago
WebKitGTK and WPE WebKit Security Advisory WSA-2026-0002
→ No new info (linked only)
Tier B
BSI Advisories2d ago
[NEU] [hoch] Apple Safari: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR3d ago
Multiples vulnérabilités dans les produits Apple (25 mars 2026)
→ No new info (linked only)
CVSS 3.14.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Published3/25/2026
Last enriched1d ago
Tags
macosprivilege escalationdenial of serviceinformation disclosuresecurity bypasscross-site scriptingios
Trending Score76
Source articles28
Independent8
Info Completeness4/14
Missing: vendor, product, versions, cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 100%