Executive brief
A vulnerability exists in Apple's web processing engine used across iPhones, iPads, Macs, and the Safari browser. If a user visits a website containing specially crafted malicious content, it could cause the browser or the underlying system process to crash unexpectedly. This primarily impacts the reliability and availability of the device's web-based services.
Technical details
A vulnerability in Apple's web content processing (likely WebKit, though not explicitly named) is caused by improper state management. An attacker can exploit this by hosting or delivering maliciously crafted web content that, when processed by a vulnerable client, triggers an unexpected process crash. While CISA-ADP classifies this as a resource exhaustion issue (CWE-770) with a CVSS of 5.5, Red Hat's analysis suggests a more severe buffer overflow (CWE-120) with a CVSS of 8.8. The issue has been addressed in Safari 26.3, iOS/iPadOS 18.7.5 and 26.3, macOS Tahoe 26.3, and visionOS 26.3 through improved state management.
Affected products
- Apple Safari 26.3
- Apple iOS 18.7.5, 26.3
- Apple iPadOS 18.7.5, 26.3
- Apple macOS Tahoe 26.3
- Apple visionOS 26.3
- Red Hat Enterprise Linux 7, 8
Timeline
- 2026-02-11: advisory: Initial publication of the vulnerability details.
- 2026-02-11: patched: Fixes released in Safari 26.3 and various Apple OS updates.