Executive brief
Apple has released security updates to address a memory management flaw across its major operating systems and the Safari web browser. An attacker could exploit this by tricking a user into visiting a specially crafted website, which may cause the browser or device to crash unexpectedly. This impact primarily affects the reliability and availability of the device's web-processing capabilities.
Technical details
A use-after-free (UAF) vulnerability exists in the memory management component of Apple's web-processing engine. The flaw is triggered when the system processes maliciously crafted web content, leading to memory corruption. An unauthenticated remote attacker can exploit this by enticing a user to visit a malicious webpage (User Interaction required). Successful exploitation primarily results in a Denial of Service (DoS) via an unexpected Safari crash, though some vendor assessments suggest higher potential impact. The issue was addressed by improving memory management in Safari 26.1 and corresponding OS updates.
Affected products
- Apple Safari before 26.1
- Apple iOS before 26.1
- Apple iPadOS before 26.1
- Apple macOS Tahoe before 26.1
- Apple visionOS before 26.1
- Apple watchOS before 26.1
- Red Hat Enterprise Linux 7, 8, 9
Timeline
- 2025-11-04: advisory: Initial publication by Apple and NVD
- 2025-11-04: patched: Fixed in Safari 26.1 and related OS versions