CVE-2026-28859General(apple / ipados)

MEDIUMCVSS 4.3 · MEDIUM

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A malicious website may be able to process restricted web content outside the sandbox.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-416CWE-787CWE-120

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • safari

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-03-25); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
ipadosiphone_osmacossafaritvosvisionoswatchos

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-25: 3Mentions · 2026-03-27: 1Mentions · 2026-04-01: 1Active Exploitation · 2026-03-27: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-25: 203-2503-2704-01
Signal classification4 categories
General
240.0%
Disclosure
120.0%
Patch
120.0%
Active Exploitation
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-253
Disclosure1General1Patch1
2026-03-271
Active Exploitation1
2026-04-011
General1
Full discourse5 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting Apple Safari and other products (CVE-2026-28859) https://vuldb.com/?ctiid.352956

    Post summary

    The post reports that CVE‑2026‑28859 has been actively targeted in offensive activities.

    0101069
    2.1K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Apple Safari and other products (CVE-2026-28859) https://vuldb.com/?id.352956

    Post summary

    Apple Safari and other products have a newly disclosed CVE-2026-28859, noted as having elevated criticality.

    01010123
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-28859 WebKit Memory Handling Vulnerability in Apple Platforms Allows Restricte... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28859 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The entry cites CVE‑2026‑28859 and provides links to vulnerability details and alerts, but offers no proof‑of‑concept, exploit code, patch information, or detailed technical specs.

    0000146
    4.0K followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 28% of vulnerabilities from past week, CVE-2026-28859 has 11 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post highlights that CVE-2026-28859 has attracted 11 articles, indicating notable attention, but provides no concrete details on exploitation, patching, or technical aspects.

    0000055
    70 followersView on X
  • Fernando Karl@fernandokarl
    Patch

    🚨 Apple users: A memória do Safari/WebKit está vulnerável! Um site malicioso pode contornar o sandbox, comprometendo sua segurança. Atualize para Safari 26.4 e outros sistemas imediatamente! 🛡️ #Cybersecurity #AppleSecurity #UpdateNow https://www.tenable.com/cve/CVE-2026-28859

    Post summary

    A memory bug in Safari/WebKit can bypass the sandbox, and users are urged to upgrade to Safari 26.4 or later to mitigate the risk.

    0000039
    257 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
Appapplesafari---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more