CVE-2026-28861
Apple Safari vulnerability analysis and mitigation

Overview

CVE-2026-28861 is a logic flaw in Apple's WebKit engine that allows a malicious website to access script message handlers intended for other origins, constituting a cross-origin data exposure issue. It was disclosed on March 24, 2026, as part of Apple's March 2026 security update batch. Affected software includes Safari (before 26.4), iOS and iPadOS (before 18.7.7 and before 26.4), macOS Tahoe (before 26.4), and visionOS (before 26.4). The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Apple Advisory - visionOS, Apple Advisory - Safari). It was discovered by Hongze Wu and Shuaike Dong from Ant Group Infrastructure Security Team, and webb, and is tracked under WebKit Bugzilla #307014 (Apple Advisory - iOS 26.4).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-site Scripting), stemming from a logic issue in WebKit's state management for script message handlers. Script message handlers in WebKit are used by native app code to receive messages from web content via window.webkit.messageHandlers; due to improper state tracking, a malicious website could access handlers registered for a different origin, violating the Same-Origin Policy boundary. Exploitation requires user interaction — specifically, a victim must visit a malicious website — and no authentication or special privileges are needed on the attacker's side. No public proof-of-concept code has been identified (Apple Advisory - iOS 18.7.7, Apple Advisory - macOS Tahoe).

Impact

Successful exploitation allows an unauthenticated remote attacker to read script message handlers registered by other origins, potentially exposing sensitive functionality or data that legitimate websites pass through those handlers (e.g., authentication tokens, session data, or application-specific messages). The confidentiality impact is rated low, with no integrity or availability impact, and the scope is unchanged — meaning exploitation is confined to the browser context without direct lateral movement to other systems. However, depending on what data is transmitted through the affected message handlers in a given application, the practical data exposure risk could be significant for hybrid apps that rely heavily on WebKit's native messaging bridge (Apple Advisory - visionOS, Apple Advisory - Safari).

Exploitation steps

  1. Reconnaissance: Identify target applications that use WebKit's window.webkit.messageHandlers API to pass sensitive data between web content and native app code (common in iOS/macOS hybrid apps and web views).
  2. Craft malicious web page: Create a webpage that attempts to enumerate or invoke script message handlers registered by other origins, exploiting the logic flaw in WebKit's state management.
  3. Deliver to victim: Host the malicious page and socially engineer the victim into visiting it using Safari or any WebKit-based browser on an unpatched Apple device.
  4. Access cross-origin handlers: Upon page load, the malicious script leverages the state management flaw to access window.webkit.messageHandlers entries intended for a different origin, potentially reading or invoking them.
  5. Exfiltrate data: Any sensitive data exposed through the accessed message handlers (e.g., tokens, session identifiers) can be exfiltrated to an attacker-controlled server (Apple Advisory - iOS 18.7.7, Apple Advisory - Safari).

Indicators of compromise

  • Network: Outbound requests from Safari or WebKit-based apps to unexpected third-party domains immediately after visiting an unfamiliar website; unusual JavaScript-initiated network calls carrying structured data resembling message handler payloads.
  • Logs: WebKit or Safari crash logs referencing script message handler access across origins; browser console errors related to cross-origin policy violations in WebKit.
  • Process: Unexpected JavaScript execution patterns in WebKit processes accessing window.webkit.messageHandlers from contexts that should not have access to those handlers.

Mitigation and workarounds

Apple has released patches addressing this vulnerability across all affected platforms: Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, and visionOS 26.4, all released on March 24, 2026 (Apple Advisory - Safari, Apple Advisory - iOS 18.7.7). No configuration-based workaround is available; updating to the patched versions is the only recommended remediation. Users and administrators should apply these updates promptly, particularly on devices running hybrid apps that use WebKit's native messaging bridge.

Community reactions

The vulnerability was part of a large March 2026 Apple security update that patched over 140 vulnerabilities across macOS, iOS, iPadOS, and other platforms, which received broad coverage from security news outlets including CyberSecurityNews and iClarified (CyberSecurityNews). The iOS 18.7.7 update was notably expanded to more devices on April 1, 2026, specifically to address the broader DarkSword exploit campaign, though CVE-2026-28861 itself is a distinct issue included in the same update batch. The SANS Internet Storm Center and CIS also published advisories covering the March 2026 Apple update batch (SANS ISC, CIS Advisory).

Additional resources


SourceThis report was generated using AI

Related Apple Safari vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64757NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64730NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64728NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64719NONEN/A
  • Apple Safari logoApple Safari
  • WebRTC
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management