Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-28861

Опубликовано: 25 мар. 2026
Источник: debian
EPSS Низкий

Описание

A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access script message handlers intended for other origins.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
webkit2gtkfixed2.52.1-1package
webkit2gtkend-of-lifebookwormpackage
webkit2gtkend-of-lifebullseyepackage
wpewebkitfixed2.52.1-1package
wpewebkitignoredtrixiepackage
wpewebkitignoredbookwormpackage
wpewebkitend-of-lifebullseyepackage

Примечания

  • https://webkitgtk.org/security/WSA-2026-0002.html

EPSS

Процентиль: 24%
0.0031
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
5 месяцев назад

A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access script message handlers intended for other origins.

CVSS3: 4.3
redhat
5 месяцев назад

A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access script message handlers intended for other origins.

CVSS3: 4.3
nvd
5 месяцев назад

A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access script message handlers intended for other origins.

CVSS3: 4.3
github
5 месяцев назад

A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access script message handlers intended for other origins.

suse-cvrf
4 месяца назад

Security update for webkit2gtk3

EPSS

Процентиль: 24%
0.0031
Низкий