CVE-2026-28971
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
8th
The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious iframe may use another website’s download settings.
| Vendor | apple |
| Product | safari |
| Ecosystems | |
| Industries | Technology |
| Published | May 11, 2026 |
| Last Updated | May 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for apple safari
Be the first to know when new medium vulnerabilities affecting apple safari are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Apple / Safari
0 < 26.5
Apple / iOS and iPadOS
0 < 26.5
Apple / macOS
0 < 26.5
Apple / visionOS
0 < 26.5