VDB

CVE-2026-28857

CVE-2026-28857 PUBLISHED CVSS 6.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.

EPSS 0.05% · 15.3th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
0.05%
15.3th percentile

Affected Products

VendorProductVersions
applemacos26.0
appleipados0
applesafari0
ApplevisionOS0
AppleSafari0
applevisionos0
ApplemacOS0
AppleiOS and iPadOS0
appleiphone_os0

Timeline

  • Mar 25, 2026 CVE Published
  • Mar 25, 2026 EPSS Score
  • Mar 25, 2026 Coalition ESS Score
  • Mar 25, 2026 PoC Published
  • Mar 26, 2026 PoC Published
  • Mar 29, 2026 Security Advisory
  • Apr 22, 2026 Distribution Patch
  • Apr 22, 2026 Security Advisory
  • Apr 24, 2026 Distribution Patch
  • Apr 27, 2026 Distribution Patch
  • Apr 27, 2026 Security Advisory
  • Apr 28, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›