Junglewise Threat Intelligence

CVE-2026-28859: Apple Safari and OS sandbox escape via improper memory handling

CVE-2026-28859 · Severity: medium · CVSS 4.3 · Published 2026-03-25

Technologies: Apple Tvos, Apple macOS, Apple Safari, Apple Iphone Os, Apple watchOS, Apple Visionos, Red Hat Enterprise Linux, Apple iPadOS. Vendors: Apple, Red Hat.

Executive brief

A vulnerability in Apple's web browser and operating systems could allow a malicious website to access restricted web content. This occurs because the software does not properly isolate certain web processes, potentially exposing sensitive information from other sites or services. Users are protected by updating their devices to the latest software versions.

Technical details

A memory handling issue in Apple's WebKit-based products (Safari, iOS, macOS, etc.) could lead to a sandbox escape. Specifically, a malicious website can bypass process isolation to access restricted web content. The vulnerability is characterized by improper memory management, with Red Hat and CISA-ADP identifying potential root causes as buffer overflows (CWE-120), out-of-bounds reads/writes (CWE-125, CWE-787), or use-after-free (CWE-416) conditions. Exploitation requires a user to visit a specially crafted malicious website. The issue is addressed in Safari 26.4 and corresponding OS updates through improved memory handling.

Affected products

  • Apple Safari 26.4
  • Apple iOS 26.4
  • Apple iPadOS 26.4
  • Apple macOS Tahoe 26.4
  • Apple tvOS 26.4
  • Apple visionOS 26.4
  • Apple watchOS 26.4
  • Red Hat Enterprise Linux

Timeline

  • 2026-03-25: disclosed
  • 2026-03-25: patched: Fixed in Safari 26.4 and related OS versions

References

Related threats