PT-2026-91698 · Apple · Ipados+5
CVE-2026-86898
·
Published
2026-09-14
·
Updated
2026-09-17
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Safari versions prior to 27
iOS versions prior to 27
iPadOS versions prior to 27
macOS Golden Gate versions prior to 27
visionOS versions prior to 27
Description
A logic issue involving state management allows for universal cross-site scripting (uXSS), a type of vulnerability where an attacker can execute malicious scripts across different origins on a browser. This occurs when a user opens a maliciously crafted webarchive file.
Recommendations
Update Safari to version 27.
Update iOS to version 27.
Update iPadOS to version 27.
Update macOS Golden Gate to version 27.
Update visionOS to version 27.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos
Safari
Ios
Ipados
Macos Golden Gate
Visionos