Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6232-1 | webkit2gtk security update |
Ubuntu USN |
USN-8237-1 | WebKitGTK vulnerabilities |
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Safari and Apple OS Sandbox Escape via Improper Memory Handling | webkitgtk: A malicious website may be able to process restricted web content outside the sandbox |
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 26 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Safari and Apple OS Sandbox Escape via Improper Memory Handling |
Wed, 25 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple ipados
Apple iphone Os |
|
| CPEs | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apple ipados
Apple iphone Os |
Wed, 25 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-125 CWE-416 CWE-787 |
|
| Metrics |
cvssV3_1
|
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple ios And Ipados Apple macos Apple safari Apple tvos Apple visionos Apple watchos |
|
| Vendors & Products |
Apple
Apple ios And Ipados Apple macos Apple safari Apple tvos Apple visionos Apple watchos |
Wed, 25 Mar 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A malicious website may be able to process restricted web content outside the sandbox. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2026-04-02T18:19:42.954Z
Reserved: 2026-03-03T16:36:03.972Z
Link: CVE-2026-28859
Updated: 2026-03-25T19:29:26.282Z
Status : Analyzed
Published: 2026-03-25T01:17:10.023
Modified: 2026-03-25T21:54:26.793
Link: CVE-2026-28859
OpenCVE Enrichment
Updated: 2026-03-31T20:09:15Z
Debian DSA
Ubuntu USN