Unrated severityNVD Advisory· Published Sep 14, 2026
CVE-2026-86898
CVE-2026-86898
Description
A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Opening a maliciously crafted webarchive file may lead to universal cross-site scripting.
Affected products
5- Range: =27
- Range: =27
- Range: =27
- Range: =27
- Range: =27
Patches
Vulnerability mechanics
References
4News mentions
1- Apple Updates Everything, (Mon, Sep 14th)SANS Internet Storm Center · Sep 14, 2026