← Back

CVE-2026-28971

nvd nist
Published: May 11, 2026Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious iframe may use another website’s download settings.

Affected (4)

4 products
Ipados
Iphone Os
Macos
Visionos
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Before 26.5
Before 26.5
From 26.0 to 26.5
Before 26.5

References (4)

Source: product-security@apple.com
Release NotesVendor Advisory
Source: product-security@apple.com
Release NotesVendor Advisory
Source: product-security@apple.com
Release NotesVendor Advisory
Source: product-security@apple.com

Timeline

No history available yet.