Junglewise Threat Intelligence

CVE-2026-28902: Apple Multiple Products Memory Handling Vulnerability in Web Content

CVE-2026-28902 · Severity: medium · CVSS 6.5 · Published 2026-05-11

Technologies: Apple Tvos, Apple macOS, Apple Safari, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A memory handling vulnerability exists in several Apple operating systems and the Safari web browser. If a user visits a website containing specially crafted malicious content, it could cause the browser or the device's system processes to crash unexpectedly. This primarily impacts the stability and availability of the affected device.

Technical details

A memory handling vulnerability exists in Apple's WebKit-related components across multiple platforms, including iOS, macOS, and Safari. The flaw is triggered when the system processes maliciously crafted web content, leading to improper memory management. An attacker can exploit this by hosting a malicious webpage that, when viewed by a victim, causes an unexpected process crash or denial-of-service condition. Apple has addressed the issue by improving memory handling logic. The vulnerability is fixed in version 26.5 of the respective operating systems and Safari.

Affected products

  • Apple iOS Before 26.5
  • Apple iPadOS Before 26.5
  • Apple macOS Tahoe Before 26.5
  • Apple tvOS Before 26.5
  • Apple visionOS Before 26.5
  • Apple watchOS Before 26.5
  • Apple Safari Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched

References

Related threats