
Apple fixed two vulnerabilities I reported affecting Safari/WebKit: CVE-2026-28953 and CVE-2026-28901. Sometimes mitigations can create new attack surfaces. https://support.apple.com/en-us/127110
Post summary
Apple has released patches for two Safari/WebKit CVEs—CVE‑2026‑28953 and CVE‑2026‑28901—though the announcement does not provide technical details of the vulnerabilities.

