Executive brief
A memory handling vulnerability exists in several Apple operating systems and the Safari web browser. If a user visits a maliciously crafted website, the browser or system process may crash unexpectedly. This primarily impacts the reliability and availability of the device during web browsing.
Technical details
A memory handling vulnerability (classified as CWE-119 and CWE-120) exists in Apple's WebKit-related components and is also noted in Red Hat Enterprise Linux distributions. The root cause is improper restriction of operations within the bounds of a memory buffer when processing web content. An unauthenticated remote attacker can exploit this by enticing a user to visit a specially crafted webpage. Successful exploitation results in a denial-of-service (DoS) condition via a process crash. Apple has addressed the issue in Safari 26.3 and various OS updates (iOS/iPadOS 18.7.5 and 26.3, macOS Tahoe 26.3, etc.) by improving memory handling.
Affected products
- Apple Safari 26.3
- Apple iOS 18.7.5, 26.3
- Apple iPadOS 18.7.5, 26.3
- Apple macOS Tahoe 26.3
- Apple tvOS 26.3
- Apple visionOS 26.3
- Apple watchOS 26.3
- Red Hat Enterprise Linux 7, 8
Timeline
- 2026-02-11: disclosed
- 2026-02-11: advisory