Junglewise Threat Intelligence

CVE-2026-28901: Apple and Red Hat multiple products buffer overflow in web content processing

CVE-2026-28901 · Severity: medium · CVSS 4.3 · Published 2026-05-11

Technologies: Red Hat Enterprise Linux, Apple Tvos, Apple macOS, Apple Safari, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Red Hat, Apple.

Executive brief

Apple and Red Hat products are affected by a memory handling vulnerability when processing web content. For users, this means that visiting a maliciously crafted website could cause their browser or operating system to crash unexpectedly. While primarily impacting system stability, such crashes can disrupt business operations and lead to unsaved data loss.

Technical details

A memory handling vulnerability, classified as a buffer overflow (CWE-120/CWE-119), exists in multiple Apple operating systems and Red Hat Enterprise Linux. The issue is triggered when the system processes maliciously crafted web content, typically via a browser or web-rendering component. An unauthenticated remote attacker can exploit this by enticing a user to visit a specially crafted webpage, leading to an unexpected process crash or denial of service. Apple addressed the issue in version 26.5 of its various platforms by improving memory handling. Red Hat has also released security advisories for affected Enterprise Linux versions.

Affected products

  • Apple iOS Before 26.5
  • Apple iPadOS Before 26.5
  • Apple macOS Tahoe Before 26.5
  • Apple Safari Before 26.5
  • Apple tvOS Before 26.5
  • Apple visionOS Before 26.5
  • Apple watchOS Before 26.5
  • Red Hat Enterprise Linux 8, 9

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: advisory
  • 2026-05-11: patched

References

Related threats