Junglewise Threat Intelligence

CVE-2026-20636: Apple and Red Hat memory handling vulnerability in web content processing

CVE-2026-20636 · Severity: medium · CVSS 6.5 · Published 2026-02-11

Technologies: Apple macOS, Apple Safari, Apple Iphone Os, Red Hat Enterprise Linux, Apple Visionos, Apple iPadOS. Vendors: Apple, Red Hat.

Executive brief

A memory handling vulnerability exists in Apple and Red Hat products when processing web content. If a user visits a specially crafted malicious website, it could cause the application or system process to crash unexpectedly. This impact primarily affects the reliability and availability of the device or browser.

Technical details

A memory handling vulnerability, classified as a buffer overflow (CWE-120) or improper restriction of operations within memory bounds (CWE-119), exists in the way various Apple operating systems and Red Hat Enterprise Linux handle web content. The issue is triggered when the system processes maliciously crafted web content, requiring minimal user interaction (such as visiting a website). An attacker can exploit this to cause an unexpected process crash, leading to a denial-of-service condition. Apple addressed the issue in version 26.3 of its various operating systems by improving memory handling. Red Hat has also released multiple security advisories (e.g., RHSA-2026:10702) to address the flaw across its Enterprise Linux distributions.

Affected products

  • Apple Safari Before 26.3
  • Apple iOS Before 26.3
  • Apple iPadOS Before 26.3
  • Apple macOS Tahoe Before 26.3
  • Apple visionOS Before 26.3
  • Red Hat Red Hat Enterprise Linux 7, 8, 9

Timeline

  • 2026-02-11: advisory: Initial NVD publication date
  • 2026-02-11: patched: Apple released fixes in Safari, iOS, iPadOS, macOS, and visionOS 26.3

References

Related threats