Apple · Ios · CVE-2026-28871
**Name of the Vulnerable Software and Affected Versions**
Safari versions prior to 26.4
iOS versions prior to 18.7.7
iPadOS versions prior to 18.7.7
macOS Tahoe versions prior to 26.4
**Description**
A logic issue exists that, if exploited via a maliciously crafted website, may lead to a cross-site scripting attack. The issue was addressed with improved checks.
**Recommendations**
Update Safari to version 26.4.
Update iOS to version 18.7.7.
Update iPadOS to version 18.7.7.
Update macOS Tahoe to version 26.4.