Junglewise Threat Intelligence

CVE-2026-28857: Apple Safari and OS memory corruption in WebKit content processing

CVE-2026-28857 · Severity: medium · CVSS 6.5 · Published 2026-03-25

Technologies: Apple macOS, Apple Safari, Apple Iphone Os, Apple Visionos, Apple iPadOS, Red Hat Enterprise Linux. Vendors: Apple, Red Hat.

Executive brief

Apple Safari and various Apple operating systems (iOS, macOS, visionOS) are affected by a memory handling vulnerability when processing web content. An attacker could use a specially crafted website to cause the browser or system processes to crash, potentially leading to a service disruption for the user. This issue also impacts certain Red Hat Enterprise Linux configurations that utilize affected web components.

Technical details

A memory handling vulnerability exists in Apple's WebKit-related components across Safari, iOS, macOS, and visionOS. The flaw, which includes characteristics of buffer overflows, out-of-bounds reads/writes, and use-after-free conditions according to secondary analysis, is triggered when the system processes maliciously crafted web content. An unauthenticated remote attacker can exploit this by enticing a user to visit a malicious webpage, resulting in an unexpected process crash (Denial of Service). While Apple's primary advisory focuses on the crash, Red Hat's enrichment suggests broader memory corruption risks (CWE-120, CWE-416). The issue is addressed in Safari 26.4 and corresponding OS updates.

Affected products

  • Apple Safari 26.4
  • Apple iOS 26.4
  • Apple iPadOS 26.4
  • Apple macOS Tahoe 26.4
  • Apple visionOS 26.4
  • Red Hat Enterprise Linux 7, 8, 9

Timeline

  • 2026-03-25: advisory: Initial disclosure by Apple and NVD publication

References

Related threats