Executive brief
Apple has released security updates for Safari and various operating systems to address a memory handling vulnerability. If a user visits a malicious website or views specially crafted web content, it could cause the application or system process to crash. In some scenarios, this could lead to unauthorized data access or broader system compromise.
Technical details
The vulnerability is classified as an 'Improper Restriction of Operations within the Bounds of a Memory Buffer' (CWE-119). It stems from insufficient memory handling when processing web content. An attacker can exploit this by enticing a user to visit a malicious webpage or interact with crafted web-based content. While the primary reported impact is an unexpected process crash (Denial of Service), the CVSS 3.1 assessment of 8.8 suggests potential for high impact on confidentiality, integrity, and availability, often associated with remote code execution in web engines. The issue was addressed through improved memory handling and bounds checking across Apple's software ecosystem.
Affected products
- Apple Safari before 26.5
- Apple iOS before 18.7.9, 26.0 to 26.5
- Apple iPadOS before 18.7.9, 26.0 to 26.5
- Apple macOS Tahoe before 26.5
- Apple tvOS before 26.5
- Apple visionOS before 26.5
- Apple watchOS before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched: Fixed in Safari 26.5, iOS 18.7.9/26.5, iPadOS 18.7.9/26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5