Junglewise Threat Intelligence

CVE-2026-20635: Apple Safari and Multiple Operating Systems Memory Corruption

CVE-2026-20635 · Severity: medium · CVSS 4.3 · Published 2026-02-11

Technologies: Apple Tvos, Apple macOS, Apple Safari, Apple watchOS, Apple Visionos, Apple iPadOS, Red Hat Enterprise Linux. Vendors: Apple, Red Hat.

Executive brief

A memory handling vulnerability exists in several Apple operating systems and the Safari web browser. If a user visits a maliciously crafted website, the browser or system process may crash unexpectedly. This primarily impacts the reliability and availability of the device during web browsing.

Technical details

A memory handling vulnerability (classified as CWE-119 and CWE-120) exists in Apple's WebKit-related components and is also noted in Red Hat Enterprise Linux distributions. The root cause is improper restriction of operations within the bounds of a memory buffer when processing web content. An unauthenticated remote attacker can exploit this by enticing a user to visit a specially crafted webpage. Successful exploitation results in a denial-of-service (DoS) condition via a process crash. Apple has addressed the issue in Safari 26.3 and various OS updates (iOS/iPadOS 18.7.5 and 26.3, macOS Tahoe 26.3, etc.) by improving memory handling.

Affected products

  • Apple Safari 26.3
  • Apple iOS 18.7.5, 26.3
  • Apple iPadOS 18.7.5, 26.3
  • Apple macOS Tahoe 26.3
  • Apple tvOS 26.3
  • Apple visionOS 26.3
  • Apple watchOS 26.3
  • Red Hat Enterprise Linux 7, 8

Timeline

  • 2026-02-11: disclosed
  • 2026-02-11: advisory

References

Related threats