Executive brief
A memory corruption vulnerability exists in Apple's web processing engine, affecting Safari and various Apple operating systems including iOS, macOS, and watchOS. An attacker could exploit this by tricking a user into visiting a malicious website, potentially leading to unauthorized access to data or system instability. This issue also impacts certain Red Hat Enterprise Linux environments that utilize related web components.
Technical details
This vulnerability is classified as an out-of-bounds write (CWE-787) or buffer overflow (CWE-120) resulting from improper memory handling when processing web content. The flaw exists in the web rendering components used across Apple's ecosystem (Safari, iOS, macOS, etc.) and has been identified in Red Hat Enterprise Linux packages. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to process specially crafted web content (e.g., visiting a malicious website). Successful exploitation could lead to memory corruption and potentially arbitrary code execution. The issue has been addressed in Safari 26.1, iOS/iPadOS 18.7.2 and 26.1, and corresponding updates for macOS, tvOS, visionOS, and watchOS.
Affected products
- Apple Safari before 26.1
- Apple iOS before 18.7.2, before 26.1
- Apple iPadOS before 18.7.2, before 26.1
- Apple macOS Tahoe before 26.1
- Apple tvOS before 26.1
- Apple visionOS before 26.1
- Apple watchOS before 26.1
- Red Hat Enterprise Linux Server 7, 8, 9
Timeline
- 2025-11-04: advisory: Initial NVD publication date