Junglewise Threat Intelligence

CVE-2026-28904: Apple and Red Hat memory corruption in web content processing

CVE-2026-28904 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Apple Tvos, Apple macOS, Apple Safari, Apple watchOS, Apple Visionos, Apple iPadOS, Red Hat Enterprise Linux. Vendors: Apple, Red Hat.

Executive brief

A memory handling vulnerability exists in Apple and Red Hat products that can be triggered when processing specially crafted web content. For business users, this could lead to application crashes or potential unauthorized access to information when browsing the web or viewing digital content. The issue affects a wide range of devices including iPhones, iPads, Macs, and enterprise Linux servers.

Technical details

This vulnerability is characterized as a memory corruption issue (CWE-119/CWE-120) resulting from improper memory handling when processing maliciously crafted web content. The root cause is a buffer overflow or similar memory boundary violation in the component responsible for rendering or parsing web data. An unauthenticated remote attacker can exploit this by enticing a user to visit a malicious website or process a crafted file, potentially leading to an unexpected process crash or arbitrary code execution. Apple addressed the issue by improving memory handling across its OS ecosystem, and Red Hat has released corresponding security updates for affected RHEL versions.

Affected products

  • Apple iOS Before 18.7.9, before 26.5
  • Apple iPadOS Before 18.7.9, before 26.5
  • Apple macOS Tahoe Before 26.5
  • Apple Safari Before 26.5
  • Apple tvOS Before 26.5
  • Apple visionOS Before 26.5
  • Apple watchOS Before 26.5
  • Red Hat Enterprise Linux 7, 8, 9

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: advisory

References

Related threats