Executive brief
A memory handling vulnerability exists in several Apple operating systems and the Safari web browser. If a user visits a website containing specially crafted malicious content, it could cause the browser or the device's system processes to crash unexpectedly. This primarily impacts the stability and availability of the affected device.
Technical details
A memory handling vulnerability exists in Apple's WebKit-related components across multiple platforms, including iOS, macOS, and Safari. The flaw is triggered when the system processes maliciously crafted web content, leading to improper memory management. An attacker can exploit this by hosting a malicious webpage that, when viewed by a victim, causes an unexpected process crash or denial-of-service condition. Apple has addressed the issue by improving memory handling logic. The vulnerability is fixed in version 26.5 of the respective operating systems and Safari.
Affected products
- Apple iOS Before 26.5
- Apple iPadOS Before 26.5
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple visionOS Before 26.5
- Apple watchOS Before 26.5
- Apple Safari Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched