Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-86898
Apple Safari vulnerability analysis and mitigation

Overview

CVE-2026-86898 is a universal cross-site scripting (UXSS) vulnerability in Apple's WebKit engine, triggered by opening a maliciously crafted webarchive file. The root cause is a logic issue in state management, which was addressed with improved state management in the patched releases. Affected products include Safari (versions before 27), iOS and iPadOS (before 27), macOS Golden Gate 27, and visionOS 27. The vulnerability was disclosed and patched on September 14, 2026. The CVSS category is estimated as HIGH; a formal CVSS base score has not yet been published (Apple Advisory iOS 27, Apple Advisory Safari 27, Apple Advisory macOS, Apple Advisory visionOS).

Technical details

The vulnerability is classified as a logic issue (CWE-840 or similar state management flaw) within WebKit's handling of webarchive files, referenced in WebKit Bugzilla #318271. When a user opens a specially crafted .webarchive file in Safari or a WebKit-based browser, the flawed state management allows JavaScript to execute in the context of arbitrary origins — bypassing the same-origin policy and enabling universal XSS. The attack is user-assisted (requires the victim to open a malicious file) but requires no authentication or special privileges. The vulnerability was discovered by Tomi Garcia (archyxsec) (Apple Advisory Safari 27).

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary JavaScript with the privileges of the affected application across any website visited in the same browser context, effectively bypassing the same-origin policy. This can lead to session hijacking, credential theft, unauthorized actions on web applications, and sensitive data exfiltration from any site the victim has open or visits. The cross-platform scope — affecting Safari on macOS, iOS, iPadOS, and visionOS — broadens the potential attack surface significantly (Apple Advisory iOS 27, Apple Advisory Safari 27).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is 0.0, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction — specifically, the victim must open a maliciously crafted webarchive file — which somewhat limits opportunistic exploitation but does not preclude targeted attacks via phishing or social engineering (Apple Advisory Safari 27).

Exploitation steps

  1. Craft a malicious webarchive file: Create a .webarchive file (Apple's proprietary web page archive format) containing embedded JavaScript payloads designed to exploit the state management flaw in WebKit's webarchive parser.
  2. Deliver the file to the target: Distribute the malicious webarchive via phishing email, malicious download link, AirDrop, or other file-sharing mechanism to a victim using an unpatched Apple device.
  3. Induce the victim to open the file: Social-engineer the victim into opening the .webarchive file in Safari or another WebKit-based application on macOS, iOS, iPadOS, or visionOS.
  4. Trigger UXSS: Upon opening, the logic flaw in WebKit's state management causes the embedded JavaScript to execute in the context of arbitrary origins, bypassing the same-origin policy.
  5. Achieve objective: The attacker's JavaScript runs with the privileges of any targeted web origin (e.g., banking, email, social media sites open in the browser), enabling session token theft, credential harvesting, or unauthorized actions on behalf of the victim (Apple Advisory Safari 27).

Mitigation and workarounds

Apple has released patches addressing this vulnerability in Safari 27, iOS 27, iPadOS 27, macOS Golden Gate 27, and visionOS 27, all released on September 14, 2026. Users should update their devices to these versions immediately via System Settings > General > Software Update (iOS/iPadOS/visionOS) or System Settings > General > Software Update (macOS). As a temporary workaround prior to patching, users should avoid opening .webarchive files received from untrusted or unknown sources. Organizations may also consider implementing application controls to restrict webarchive file handling until devices are updated (Apple Advisory iOS 27, Apple Advisory Safari 27, Apple Advisory macOS, Apple Advisory visionOS).

Community reactions

Coverage of CVE-2026-86898 appeared in security-focused media shortly after Apple's September 14, 2026 release, including a roundup of iOS 27 and iPadOS 27 security fixes on 9to5Mac. Threat intelligence aggregators such as radar.offseq.com catalogued the vulnerability on the day of disclosure. No notable independent researcher commentary or significant social media discussion beyond standard vulnerability tracking has been identified at this time (9to5Mac).

Additional resources


SourceThis report was generated using AI

Related Apple Safari vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-65391HIGH8.8
  • Apple Safari logoApple Safari
  • WebRTC
NoYesSep 14, 2026
CVE-2026-84635MEDIUM6.5
  • Apple Safari logoApple Safari
  • webkitgtk
NoYesSep 14, 2026
CVE-2026-86897MEDIUM5.5
  • Apple Safari logoApple Safari
  • Safe Browsing
NoYesSep 14, 2026
CVE-2026-86898MEDIUM5.4
  • Apple Safari logoApple Safari
  • WebKit
NoYesSep 14, 2026
CVE-2026-84518MEDIUM4.3
  • Apple Safari logoApple Safari
  • cpe:2.3:a:apple:safari
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management