Apple iOS/macOS iPadOS visionOS iframe download settings flaw before 26.5
CVE-2026-28971 Published on May 11, 2026
The issue was addressed with improved UI handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious iframe may use another websites download settings.
Products Associated with CVE-2026-28971
Want to know whenever a new CVE is published for Apple products? stack.watch will email you.
Affected Versions
Apple iOS and iPadOS:- Before 26.5 is affected.
- Before 26.5 is affected.
- Before 26.5 is affected.