PT-2026-91698 · Apple · Ipados+5

CVE-2026-86898

·

Published

2026-09-14

·

Updated

2026-09-17

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Safari versions prior to 27 iOS versions prior to 27 iPadOS versions prior to 27 macOS Golden Gate versions prior to 27 visionOS versions prior to 27
Description A logic issue involving state management allows for universal cross-site scripting (uXSS), a type of vulnerability where an attacker can execute malicious scripts across different origins on a browser. This occurs when a user opens a maliciously crafted webarchive file.
Recommendations Update Safari to version 27. Update iOS to version 27. Update iPadOS to version 27. Update macOS Golden Gate to version 27. Update visionOS to version 27.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86898

Affected Products

Apple Macos
Safari
Ios
Ipados
Macos Golden Gate
Visionos