A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access script message handlers intended for other origins.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Safari | Apple | * | 26.4 (excluding) |
| Ipados | Apple | * | 18.7.7 (excluding) |
| Ipados | Apple | 26.0 (including) | 26.4 (excluding) |
| Iphone_os | Apple | * | 18.7.7 (excluding) |
| Iphone_os | Apple | 26.0 (including) | 26.4 (excluding) |
| Macos | Apple | * | 26.4 (excluding) |
| Visionos | Apple | * | 26.4 (excluding) |
| Qtwebkit-opensource-src | Ubuntu | esm-apps/bionic | * |
| Qtwebkit-opensource-src | Ubuntu | esm-apps/focal | * |
| Qtwebkit-opensource-src | Ubuntu | esm-apps/jammy | * |
| Qtwebkit-opensource-src | Ubuntu | esm-apps/noble | * |
| Qtwebkit-opensource-src | Ubuntu | esm-infra-legacy/xenial | * |
| Qtwebkit-opensource-src | Ubuntu | esm-infra/xenial | * |
| Qtwebkit-opensource-src | Ubuntu | jammy | * |
| Qtwebkit-opensource-src | Ubuntu | noble | * |
| Qtwebkit-source | Ubuntu | esm-apps-legacy/xenial | * |
| Qtwebkit-source | Ubuntu | esm-apps/bionic | * |
| Qtwebkit-source | Ubuntu | esm-apps/xenial | * |
| Webkit2gtk | Ubuntu | devel | * |
| Webkit2gtk | Ubuntu | esm-infra-legacy/xenial | * |
| Webkit2gtk | Ubuntu | esm-infra/bionic | * |
| Webkit2gtk | Ubuntu | esm-infra/focal | * |
| Webkit2gtk | Ubuntu | esm-infra/xenial | * |
| Webkit2gtk | Ubuntu | jammy | * |
| Webkit2gtk | Ubuntu | noble | * |
| Webkit2gtk | Ubuntu | questing | * |
| Webkit2gtk | Ubuntu | resolute | * |
| Webkit2gtk | Ubuntu | upstream | * |
| Webkitgtk | Ubuntu | esm-apps-legacy/xenial | * |
| Webkitgtk | Ubuntu | esm-apps/bionic | * |
| Webkitgtk | Ubuntu | esm-apps/xenial | * |
| Wpewebkit | Ubuntu | esm-apps/focal | * |
| Wpewebkit | Ubuntu | esm-apps/jammy | * |
| Wpewebkit | Ubuntu | jammy | * |