Junglewise Threat Intelligence

CVE-2026-28903: Apple and Red Hat Multiple Products Buffer Overflow in Web Content Processing

CVE-2026-28903 · Severity: medium · CVSS 6.5 · Published 2026-05-11

Technologies: Apple Tvos, Apple macOS, Apple Safari, Apple watchOS, Apple Visionos, Apple iPadOS, Red Hat Enterprise Linux. Vendors: Apple, Red Hat.

Executive brief

Apple and Red Hat products are affected by a memory handling vulnerability that occurs when processing web content. For users of iPhones, iPads, Macs, and Red Hat Enterprise Linux, visiting a malicious website could cause applications or the system process to crash unexpectedly. This impact primarily affects the reliability and availability of the device rather than direct data theft.

Technical details

A memory handling vulnerability (classified as CWE-119 and CWE-120) exists in multiple Apple operating systems and Red Hat Enterprise Linux. The flaw is triggered when the system processes maliciously crafted web content, leading to improper restriction of operations within the bounds of a memory buffer. An unauthenticated remote attacker can exploit this by enticing a user to visit a specially crafted webpage, resulting in an unexpected process crash (Denial of Service). Apple addressed the issue with improved memory handling in Safari 26.5 and corresponding OS updates. Red Hat has also released security advisories for affected Enterprise Linux versions.

Affected products

  • Apple Safari Before 26.5
  • Apple iOS Before 18.7.9, Before 26.5
  • Apple iPadOS Before 18.7.9, Before 26.5
  • Apple macOS Tahoe Before 26.5
  • Apple tvOS Before 26.5
  • Apple visionOS Before 26.5
  • Apple watchOS Before 26.5
  • Red Hat Enterprise Linux 7, 8, 9

Timeline

  • 2026-05-11: advisory: Initial publication date

References

Related threats