Executive brief
A memory management vulnerability exists in Apple's web browser engine and operating systems. If a user visits a specially crafted website, the browser or device may crash unexpectedly. This could disrupt operations or lead to a temporary denial of service on affected iPhones, iPads, Macs, and Apple Watches.
Technical details
A use-after-free vulnerability exists in the memory management component of Apple's web processing engine. The flaw is triggered when the system processes maliciously crafted web content, leading to an unexpected Safari crash or denial of service. The attack vector is network-based and requires minimal user interaction (visiting a malicious site). Apple has addressed this issue by improving memory management in Safari 26.1, iOS/iPadOS 18.7.2, and other OS updates. Red Hat has also identified impact on certain Enterprise Linux versions that may utilize affected components.
Affected products
- Apple Safari Before 26.1
- Apple iOS Before 18.7.2, Before 26.1
- Apple iPadOS Before 18.7.2, Before 26.1
- Apple macOS Tahoe Before 26.1
- Apple visionOS Before 26.1
- Apple watchOS Before 26.1
- Red Hat Enterprise Linux 7, 8
Timeline
- 2025-11-04: disclosed: Initial advisory publication