Executive brief
Apple Safari and various Apple operating systems are affected by a memory handling vulnerability when processing web content. An attacker could exploit this by tricking a user into visiting a malicious website, which would cause the Safari browser to crash unexpectedly. While this primarily impacts the availability of the browser, it can disrupt user operations and web-based services on iPhones, iPads, Macs, and other Apple devices.
Technical details
A memory handling vulnerability exists in Apple's web processing components (Safari/WebKit) across multiple platforms. The flaw is triggered when the engine processes maliciously crafted web content, leading to an unexpected process crash or denial-of-service. The root cause was identified as improper memory handling, which Apple addressed by improving how the software manages memory during content rendering. An attacker can exploit this remotely via a network vector, though it requires user interaction (visiting a malicious site). The issue is tracked as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and has been patched in Safari 18.5 and related OS updates.
Affected products
- Apple Safari before 18.5
- Apple iOS before 18.5
- Apple iPadOS before 18.5
- Apple macOS Sequoia before 15.5
- Apple tvOS before 18.5
- Apple visionOS before 2.5
- Apple watchOS before 11.5
Timeline
- 2025-05-12: disclosed
- 2025-05-12: patched