CVE-2026-28971
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
4th
The issue was addressed with improved UI handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious iframe may use another website’s download settings.
| Vendor | apple |
| Product | ios and ipados |
| Ecosystems | |
| Industries | Technology |
| Published | May 11, 2026 |
| Last Updated | May 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for apple ios and ipados
Be the first to know when new medium vulnerabilities affecting apple ios and ipados are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Apple / iOS and iPadOS
0 < 26.5
Apple / macOS
0 < 26.5
Apple / visionOS
0 < 26.5