
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-86898 is a universal cross-site scripting (UXSS) vulnerability in Apple's WebKit engine, triggered by opening a maliciously crafted webarchive file. The root cause is a logic issue in state management, which was addressed with improved state management in the patched releases. Affected products include Safari (versions before 27), iOS and iPadOS (before 27), macOS Golden Gate 27, and visionOS 27. The vulnerability was disclosed and patched on September 14, 2026. The CVSS category is estimated as HIGH; a formal CVSS base score has not yet been published (Apple Advisory iOS 27, Apple Advisory Safari 27, Apple Advisory macOS, Apple Advisory visionOS).
The vulnerability is classified as a logic issue (CWE-840 or similar state management flaw) within WebKit's handling of webarchive files, referenced in WebKit Bugzilla #318271. When a user opens a specially crafted .webarchive file in Safari or a WebKit-based browser, the flawed state management allows JavaScript to execute in the context of arbitrary origins — bypassing the same-origin policy and enabling universal XSS. The attack is user-assisted (requires the victim to open a malicious file) but requires no authentication or special privileges. The vulnerability was discovered by Tomi Garcia (archyxsec) (Apple Advisory Safari 27).
Successful exploitation allows an unauthenticated attacker to execute arbitrary JavaScript with the privileges of the affected application across any website visited in the same browser context, effectively bypassing the same-origin policy. This can lead to session hijacking, credential theft, unauthorized actions on web applications, and sensitive data exfiltration from any site the victim has open or visits. The cross-platform scope — affecting Safari on macOS, iOS, iPadOS, and visionOS — broadens the potential attack surface significantly (Apple Advisory iOS 27, Apple Advisory Safari 27).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is 0.0, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction — specifically, the victim must open a maliciously crafted webarchive file — which somewhat limits opportunistic exploitation but does not preclude targeted attacks via phishing or social engineering (Apple Advisory Safari 27).
.webarchive file (Apple's proprietary web page archive format) containing embedded JavaScript payloads designed to exploit the state management flaw in WebKit's webarchive parser..webarchive file in Safari or another WebKit-based application on macOS, iOS, iPadOS, or visionOS.Apple has released patches addressing this vulnerability in Safari 27, iOS 27, iPadOS 27, macOS Golden Gate 27, and visionOS 27, all released on September 14, 2026. Users should update their devices to these versions immediately via System Settings > General > Software Update (iOS/iPadOS/visionOS) or System Settings > General > Software Update (macOS). As a temporary workaround prior to patching, users should avoid opening .webarchive files received from untrusted or unknown sources. Organizations may also consider implementing application controls to restrict webarchive file handling until devices are updated (Apple Advisory iOS 27, Apple Advisory Safari 27, Apple Advisory macOS, Apple Advisory visionOS).
Coverage of CVE-2026-86898 appeared in security-focused media shortly after Apple's September 14, 2026 release, including a roundup of iOS 27 and iPadOS 27 security fixes on 9to5Mac. Threat intelligence aggregators such as radar.offseq.com catalogued the vulnerability on the day of disclosure. No notable independent researcher commentary or significant social media discussion beyond standard vulnerability tracking has been identified at this time (9to5Mac).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."