CVE-2026-28857Patch(apple / ipados)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-416CWE-787CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • safari

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-25); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_osmacossafarivisionos

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-25: 1Mentions · 2026-03-26: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-25: 103-2503-26
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-251
Patch1
2026-03-261
Disclosure1
Full discourse2 posts
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting Apple Safari and other products (CVE-2026-28857) https://vuldb.com/?id.352959

    Post summary

    The post announces an increased severity for the newly identified Apple Safari vulnerability CVE-2026-28857 based on a VulDB link.

    0000070
    2.1K followersView on X
  • Fernando Karl@fernandokarl
    Patch

    ⚠️ Uma falha de memória no Safari pode causar crashes ao abrir conteúdos maliciosos! 🛑 Atualize para as versões 26.4 de Safari, iOS, iPadOS e macOS para se proteger. #Cibersegurança #AtualizaçãoUrgente 👉 https://www.tenable.com/cve/CVE-2026-28857

    Post summary

    Users are warned of a Safari memory bug (CVE-2026-28857) that can crash devices on malicious content, and advised to update to version 26.4, with no mention of active exploitation or provided PoC.

    00000101
    257 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
Appapplesafari---
OSapplevisionos---

Explore more