Executive brief
Safari is Apple's web browser used to browse the internet on iPhones, iPads, and Macs. A logic flaw in how Safari handles maliciously crafted webarchive files can allow attackers to inject malicious scripts that bypass security protections and execute arbitrary code in the context of any website, potentially stealing user credentials, financial data, or session information.
Technical details
A logic issue in Safari's webarchive file processing fails to properly validate state management when opening specially crafted webarchive files. This permits universal cross-site scripting (UXSS), where an attacker can inject JavaScript that executes in the origin context of arbitrary websites, bypassing the same-origin policy. The vulnerability is triggered when a user opens a malicious webarchive file, with no additional user interaction or authentication required beyond the file open action. Exploitation allows an attacker to read sensitive data from visited websites, modify page content, steal session tokens, or perform actions on behalf of the user. Patches are available in Safari 27, iOS 27, iPadOS 27, macOS Golden Gate 27, and visionOS 27 (all released September 14, 2026).
Affected products
- Apple Safari before 27
- Apple iOS before 27
- Apple iPadOS before 27
- Apple macOS Golden Gate before 27
- Apple visionOS before 27
Timeline
- 2026-09-14: disclosed: CVE-2026-86898 disclosed; patches released simultaneously
- 2026-09-14: patched: Safari 27, iOS 27, iPadOS 27, macOS Golden Gate 27, visionOS 27 released with fix