Junglewise Threat Intelligence

CVE-2026-28883: Apple WebKit use after free in web content processing

CVE-2026-28883 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Apple Tvos, Apple macOS, Apple Safari, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS, Red Hat Enterprise Linux. Vendors: Apple, Red Hat.

Executive brief

A memory management vulnerability exists in Apple's web processing engine used across Safari, iPhones, iPads, and Macs. An attacker could exploit this by tricking a user into visiting a malicious website, potentially causing the browser or device to crash. In some scenarios, this could lead to unauthorized access to data or the ability to run malicious code on the device.

Technical details

A use-after-free (UAF) vulnerability was identified in the memory management component of Apple's web content processing engine (WebKit). The flaw is triggered when the system attempts to access memory that has already been deallocated during the processing of specially crafted web content. This is a network-based attack vector that typically requires a user to visit a malicious webpage. Successful exploitation can result in an unexpected process crash or potentially arbitrary code execution. Apple has addressed the issue with improved memory management in Safari 26.5 and corresponding OS updates. Red Hat has also identified impact on various Enterprise Linux versions that utilize affected components.

Affected products

  • Apple Safari 26.5
  • Apple iOS 26.5
  • Apple iPadOS 26.5
  • Apple macOS Tahoe 26.5
  • Apple tvOS 26.5
  • Apple visionOS 26.5
  • Apple watchOS 26.5
  • Red Hat Enterprise Linux 7, 8, 9

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: advisory
  • 2026-05-11: patched

References

Related threats