Executive brief
Apple has released security updates to address a memory handling issue across its major operating systems and the Safari web browser. If a user visits a specially crafted, malicious website, the browser or device may experience an unexpected crash. This could lead to a temporary disruption of service or loss of unsaved work for users on affected iPhones, iPads, Macs, and Apple Watches.
Technical details
A memory handling vulnerability (classified as CWE-119/CWE-120) exists in Apple's WebKit-based components and various operating systems. The flaw is triggered when the system processes maliciously crafted web content, leading to improper restriction of operations within the bounds of a memory buffer. An unauthenticated remote attacker can exploit this by enticing a user to visit a malicious webpage, resulting in an unexpected application or system crash (Denial of Service). Apple addressed the issue with improved memory handling in Safari 18.6, iOS/iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, and watchOS 11.6. Red Hat has also identified impact on certain Enterprise Linux versions.
Affected products
- Apple Safari Before 18.6
- Apple iOS and iPadOS Before 18.6
- Apple macOS Sequoia Before 15.6
- Apple tvOS Before 18.6
- Apple visionOS Before 2.6
- Apple watchOS Before 11.6
- Red Hat Enterprise Linux 8, 7 ELS
Timeline
- 2025-07-30: advisory
- 2025-07-30: patched