Executive brief
A memory handling vulnerability exists in several Apple operating systems and the Safari web browser. An attacker could exploit this by tricking a user into visiting a malicious website or viewing specially crafted web content. Successful exploitation could allow an attacker to compromise the device, potentially leading to unauthorized access to data or system instability.
Technical details
A memory corruption vulnerability, specifically identified as a buffer overflow (CWE-119/CWE-120), exists in Apple's web content processing components. The issue stems from improper memory handling when parsing maliciously crafted web content. An unauthenticated remote attacker can exploit this by enticing a user to visit a malicious webpage (User Interaction required). Successful exploitation may lead to arbitrary code execution or memory corruption on the target device. Apple has addressed this issue by improving memory handling in Safari 18.6, iOS 18.6, iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, and watchOS 11.6.
Affected products
- Apple Safari before 18.6
- Apple iOS before 18.6
- Apple iPadOS before 18.6
- Apple macOS Sequoia before 15.6
- Apple tvOS before 18.6
- Apple visionOS before 2.6
- Apple watchOS before 11.6
Timeline
- 2025-07-30: advisory: Initial disclosure by Apple and NVD.
- 2025-07-30: patched: Fixes released in various Apple OS updates.