Skip to content
AppleCVE-2026-86898

Apple Safari: cross-site scripting

Medium5.4CVE-2026-86898 · Published Sep 14, 2026 · updated Sep 18, 2026

A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Opening a maliciously crafted webarchive file may lead to universal cross-site scripting.

Apple advisory

Affected versions

PackageAffectedFixed in
Safari
Product
< 2727
iOS and iPadOS
Product
< 2727
macOS
Product
< 2727
visionOS
Product
< 2727
Details and references

More Apple advisories

All Apple
Advisory
Apple macOS: path traversal
Medium5.5Sep 14
Apple iOS and iPadOS: out-of-bounds read
Medium5.5Sep 14
A privacy issue was addressed with improved state management
High7.5Sep 14
Apple iOS and iPadOS: improper access control
Medium5.5Sep 14
Apple macOS: protection mechanism failure
Medium4.4Sep 14
Apple macOS: path traversal
Medium5.5Sep 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.