
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28861 is a logic flaw in Apple's WebKit engine that allows a malicious website to access script message handlers intended for other origins, constituting a cross-origin data exposure issue. It was disclosed on March 24, 2026, as part of Apple's March 2026 security update batch. Affected software includes Safari (before 26.4), iOS and iPadOS (before 18.7.7 and before 26.4), macOS Tahoe (before 26.4), and visionOS (before 26.4). The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Apple Advisory - visionOS, Apple Advisory - Safari). It was discovered by Hongze Wu and Shuaike Dong from Ant Group Infrastructure Security Team, and webb, and is tracked under WebKit Bugzilla #307014 (Apple Advisory - iOS 26.4).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-site Scripting), stemming from a logic issue in WebKit's state management for script message handlers. Script message handlers in WebKit are used by native app code to receive messages from web content via window.webkit.messageHandlers; due to improper state tracking, a malicious website could access handlers registered for a different origin, violating the Same-Origin Policy boundary. Exploitation requires user interaction — specifically, a victim must visit a malicious website — and no authentication or special privileges are needed on the attacker's side. No public proof-of-concept code has been identified (Apple Advisory - iOS 18.7.7, Apple Advisory - macOS Tahoe).
Successful exploitation allows an unauthenticated remote attacker to read script message handlers registered by other origins, potentially exposing sensitive functionality or data that legitimate websites pass through those handlers (e.g., authentication tokens, session data, or application-specific messages). The confidentiality impact is rated low, with no integrity or availability impact, and the scope is unchanged — meaning exploitation is confined to the browser context without direct lateral movement to other systems. However, depending on what data is transmitted through the affected message handlers in a given application, the practical data exposure risk could be significant for hybrid apps that rely heavily on WebKit's native messaging bridge (Apple Advisory - visionOS, Apple Advisory - Safari).
window.webkit.messageHandlers API to pass sensitive data between web content and native app code (common in iOS/macOS hybrid apps and web views).window.webkit.messageHandlers entries intended for a different origin, potentially reading or invoking them.window.webkit.messageHandlers from contexts that should not have access to those handlers.Apple has released patches addressing this vulnerability across all affected platforms: Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, and visionOS 26.4, all released on March 24, 2026 (Apple Advisory - Safari, Apple Advisory - iOS 18.7.7). No configuration-based workaround is available; updating to the patched versions is the only recommended remediation. Users and administrators should apply these updates promptly, particularly on devices running hybrid apps that use WebKit's native messaging bridge.
The vulnerability was part of a large March 2026 Apple security update that patched over 140 vulnerabilities across macOS, iOS, iPadOS, and other platforms, which received broad coverage from security news outlets including CyberSecurityNews and iClarified (CyberSecurityNews). The iOS 18.7.7 update was notably expanded to more devices on April 1, 2026, specifically to address the broader DarkSword exploit campaign, though CVE-2026-28861 itself is a distinct issue included in the same update batch. The SANS Internet Storm Center and CIS also published advisories covering the March 2026 Apple update batch (SANS ISC, CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."