🔐 CVE Alert

CVE-2026-28971

MEDIUM 4.3
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
8th

The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious iframe may use another website’s download settings.

Vendor apple
Product safari
Ecosystems
Industries
Technology
Published May 11, 2026
Last Updated May 13, 2026
Stay Ahead of the Next One

Get instant alerts for apple safari

Be the first to know when new medium vulnerabilities affecting apple safari are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apple / Safari
0 < 26.5
Apple / iOS and iPadOS
0 < 26.5
Apple / macOS
0 < 26.5
Apple / visionOS
0 < 26.5

References

NVD ↗ CVE.org ↗ EPSS Data ↗
support.apple.com: https://support.apple.com/en-us/127110 support.apple.com: https://support.apple.com/en-us/127115 support.apple.com: https://support.apple.com/en-us/127120 support.apple.com: https://support.apple.com/en-us/127121