CVE-2026-28871
Apple Safari vulnerability analysis and mitigation

Overview

CVE-2026-28871 is a cross-site scripting (XSS) vulnerability in Apple's WebKit browser engine that allows a malicious website to execute a cross-site scripting attack when visited by a user. The flaw stems from a logic issue in WebKit that was addressed with improved checks (WebKit Bugzilla: 305859). It was discovered by researcher @hamayanhamayan and disclosed on March 24, 2026, as part of Apple's March 2026 security update batch. Affected products include Safari prior to 26.4, iOS and iPadOS prior to 18.7.7 (legacy branch) or 26.4 (new branch), and macOS Tahoe prior to 26.4. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Apple iOS 26.4 Advisory, Apple Safari 26.4 Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-Site Scripting) and resides in the WebKit rendering engine. A logic flaw in WebKit's state management allows a maliciously crafted website to trigger a cross-site scripting attack when rendered by an affected browser. Exploitation requires user interaction — specifically, a victim must visit a specially crafted malicious webpage — and no authentication or elevated privileges are required on the attacker's part. The attack vector is network-based, and the scope is unchanged, meaning the impact is confined to the affected browser context (Apple iOS 26.4 Advisory, Apple macOS Tahoe 26.4 Advisory, Feedly).

Impact

Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of a victim's browser session, potentially leading to unauthorized access to sensitive information rendered in the browser, session token theft, or manipulation of web content. The confidentiality impact is rated as low, with no integrity or availability impact assessed. The vulnerability does not enable lateral movement or direct system compromise, but could be chained with other vulnerabilities for broader attacks (Apple iOS 26.4 Advisory, Feedly).

Mitigation and workarounds

Apple has released patches addressing this vulnerability across all affected platforms. Users should update to the following versions or later: Safari 26.4 (for macOS Sonoma and macOS Sequoia), iOS 18.7.7 and iPadOS 18.7.7 (for devices on the legacy 18.x branch), iOS 26.4 and iPadOS 26.4 (for devices on the 26.x branch), and macOS Tahoe 26.4. No configuration-based workarounds have been published; updating to a patched version is the recommended and only known remediation (Apple iOS 26.4 Advisory, Apple iOS 18.7.7 Advisory, Apple macOS Tahoe 26.4 Advisory, Apple Safari 26.4 Advisory).

Community reactions

The March 2026 Apple security update batch, which included CVE-2026-28871, received broad coverage in the security community due to the large number of vulnerabilities patched (over 140 across macOS, iOS, iPadOS, and tvOS). Media outlets such as iClarified and SecureReading covered the iOS 18.7.7 and iOS 26.4 releases, noting the significance of the DarkSword-related fixes included in the same update cycle. The SANS Internet Storm Center also published a diary entry covering the March 2026 Apple updates (SANS ISC Diary). CVE-2026-28871 itself did not generate notable standalone commentary, consistent with its medium severity rating and lack of known exploitation.

Additional resources


SourceThis report was generated using AI

Related Apple Safari vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64757NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64730NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64728NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64719NONEN/A
  • Apple Safari logoApple Safari
  • WebRTC
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management