Executive brief
Apple and Red Hat products are affected by a memory handling vulnerability that can be triggered when processing specially crafted web content. For a typical user, this means that visiting a malicious website could cause their web browser or operating system components to crash unexpectedly. This impact primarily affects the reliability and availability of the device rather than direct data theft.
Technical details
A memory handling vulnerability exists in multiple Apple operating systems and Red Hat Enterprise Linux. The flaw is characterized by improper restriction of operations within the bounds of a memory buffer (CWE-119) and potential use-after-free (CWE-416) or out-of-bounds write (CWE-787) conditions. An attacker can exploit this by enticing a user to process maliciously crafted web content, leading to an unexpected process crash or denial of service. The issue was addressed by Apple through improved memory handling in Safari 26.3, iOS 18.7.5/26.3, macOS Tahoe 26.3, and visionOS 26.3. Red Hat has also released corresponding security errata for affected RHEL versions.
Affected products
- Apple Safari 26.3
- Apple iOS 18.7.5, 26.3
- Apple iPadOS 18.7.5, 26.3
- Apple macOS Tahoe 26.3
- Apple visionOS 26.3
- Red Hat Enterprise Linux 7, 8
Timeline
- 2026-02-11: disclosed
- 2026-02-11: patched