Junglewise Threat Intelligence

CVE-2026-28971: Apple Multiple Operating Systems Improper UI Handling in iframes

CVE-2026-28971 · Severity: medium · CVSS 4.3 · Published 2026-05-11

Technologies: Apple macOS, Apple Safari, Apple Iphone Os, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability in Apple's web browser engine could allow a malicious website to interfere with how files are downloaded. By using a hidden frame, an attacker's site could inherit or manipulate the download settings of a different, legitimate website. This could lead to files being saved in unexpected locations or with incorrect security settings without the user's knowledge.

Technical details

A logic vulnerability exists in the UI handling of iframes across multiple Apple platforms. A malicious website can utilize an iframe to inherit or leverage the download settings associated with a different origin. This issue stems from inconsistent state management or improper isolation of download preferences between parent and child frames. An attacker could exploit this by tricking a user into visiting a malicious page that embeds a target site in an iframe to manipulate download behavior. The issue was addressed by improving UI handling and state management in Safari 26.5 and related OS updates.

Affected products

  • Apple iOS < 26.5
  • Apple iPadOS < 26.5
  • Apple macOS Tahoe < 26.5
  • Apple visionOS < 26.5
  • Apple Safari < 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched

References

Related threats