{"id":"CVE-2026-86898","title":"A logic issue was addressed with improved state management","summary":"A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Opening a maliciously crafted webarchive file may lead to universal cross-site scripting.","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"apple","product":"safari","affected":["safari < 27.0","ipados < 27.0","iphone_os < 27.0","macos < 27.0","visionos < 27.0"],"patched":["safari 27.0","ipados 27.0","iphone_os 27.0","macos 27.0","visionos 27.0"],"published":"2026-09-14","updated":"2026-09-18","sourceUpdated":"2026-09-18T15:07:11.860","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86898","references":[{"url":"https://support.apple.com/en-us/149034","label":"product-security@apple.com"},{"url":"https://support.apple.com/en-us/149035","label":"product-security@apple.com"},{"url":"https://support.apple.com/en-us/149038","label":"product-security@apple.com"},{"url":"https://support.apple.com/en-us/149039","label":"product-security@apple.com"}],"tags":["nvd","cve.org"],"epss":0.0019,"epssPercentile":0.08895,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-17T15:56:23.950479Z"},"ingestedAt":"2026-09-14T21:15:17.486Z","slug":"CVE-2026-86898","body":"## Overview\n\nA logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Opening a maliciously crafted webarchive file may lead to universal cross-site scripting.\n\n## Affected\n\n- `safari < 27.0`\n- `ipados < 27.0`\n- `iphone_os < 27.0`\n- `macos < 27.0`\n- `visionos < 27.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `safari 27.0`\n- `ipados 27.0`\n- `iphone_os 27.0`\n- `macos 27.0`\n- `visionos 27.0`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":206243,"id":"CVE-2026-86898","ts":1789662143376,"field":"cvss","old":null,"new":"5.4"},{"seq":206242,"id":"CVE-2026-86898","ts":1789662143376,"field":"severity","old":"none","new":"medium"}]}