SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86898

UNKNOWN · CVSS N/A EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A logic flaw in Safari, iOS, iPadOS, macOS, and visionOS allows for universal cross-site scripting when a maliciously crafted webarchive file is opened. This vulnerability could enable attackers to execute arbitrary scripts in the context of the user's session, potentially leading to data theft or session hijacking. Users and organizations utilizing these Apple platforms should prioritize updating to the latest versions to mitigate this risk.

CVE
CVE-2026-86898
Severity
UNKNOWN
CVSS
N/A
EPSS
0.15%

Original NVD Description

A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Opening a maliciously crafted webarchive file may lead to universal cross-site scripting.