VYPR
Medium severity4.3NVD Advisory· Published May 11, 2026· Updated May 13, 2026

CVE-2026-28971

CVE-2026-28971

Description

The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious iframe may use another website’s download settings.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

1