Executive brief
A memory management vulnerability exists in several Apple operating systems and the Safari web browser. If a user visits a maliciously crafted website, the application or system process may crash unexpectedly. This could lead to service interruptions or temporary loss of access to the device's features.
Technical details
A use-after-free (UAF) vulnerability, identified as CWE-416, exists in Apple's memory management logic across multiple platforms including iOS, macOS, and Safari. The vulnerability is triggered when the system processes specially crafted web content, leading to memory corruption. An unauthenticated remote attacker can exploit this by enticing a user to visit a malicious webpage, resulting in an unexpected process crash (Denial of Service). While Apple's primary advisory focuses on process stability, Red Hat's assessment suggests a higher potential impact including confidentiality and integrity risks. The issue has been addressed in Safari 26.2, iOS/iPadOS 18.7.2, and other concurrent Apple OS updates through improved memory management.
Affected products
- Apple iOS Before 18.7.2, Before 26.2
- Apple iPadOS Before 18.7.2, Before 26.2
- Apple Safari Before 26.2
- Apple macOS Tahoe Before 26.2
- Apple visionOS Before 26.2
- Apple watchOS Before 26.2
- Red Hat Enterprise Linux 7, 8, 9
Timeline
- 2025-12-12: advisory: Initial NVD publication date