A vulnerability classified as problematic was found in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS up to 18.7.8/26.4. This affects an unknown function of the component Website Handler. Such manipulation leads to information disclosure.

This vulnerability is referenced as CVE-2026-28920. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised.