Executive brief
A memory management vulnerability exists in Apple's web processing engine used across Safari, iPhones, iPads, and Macs. An attacker could exploit this by tricking a user into visiting a malicious website, potentially causing the browser or device to crash. In some scenarios, this could lead to unauthorized access to data or the ability to run malicious code on the device.
Technical details
A use-after-free (UAF) vulnerability was identified in the memory management component of Apple's web content processing engine (WebKit). The flaw is triggered when the system attempts to access memory that has already been deallocated during the processing of specially crafted web content. This is a network-based attack vector that typically requires a user to visit a malicious webpage. Successful exploitation can result in an unexpected process crash or potentially arbitrary code execution. Apple has addressed the issue with improved memory management in Safari 26.5 and corresponding OS updates. Red Hat has also identified impact on various Enterprise Linux versions that utilize affected components.
Affected products
- Apple Safari 26.5
- Apple iOS 26.5
- Apple iPadOS 26.5
- Apple macOS Tahoe 26.5
- Apple tvOS 26.5
- Apple visionOS 26.5
- Apple watchOS 26.5
- Red Hat Enterprise Linux 7, 8, 9
Timeline
- 2026-05-11: disclosed
- 2026-05-11: advisory
- 2026-05-11: patched