CyberRota Analysis
AI-GeneratedA logic flaw in Safari, iOS, iPadOS, macOS, and visionOS allows for universal cross-site scripting when a maliciously crafted webarchive file is opened. This vulnerability could enable attackers to execute arbitrary scripts in the context of the user's session, potentially leading to data theft or session hijacking. Users and organizations utilizing these Apple platforms should prioritize updating to the latest versions to mitigate this risk.
Original NVD Description
A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Opening a maliciously crafted webarchive file may lead to universal cross-site scripting.