Executive brief
A memory handling vulnerability exists in Apple and Red Hat products when processing web content. If a user visits a malicious website or views specially crafted content, it could cause the application or system process to crash. In some scenarios, this could lead to unauthorized access to information or broader system instability.
Technical details
This vulnerability is a memory corruption issue, specifically identified as a buffer overflow (CWE-120) or improper restriction of operations within memory bounds (CWE-119). The flaw exists in the way the system handles memory during the processing of web content. An unauthenticated remote attacker can exploit this by providing maliciously crafted web content, which triggers an unexpected process crash or potentially allows for arbitrary code execution or information disclosure. Apple addressed the issue in Safari 26.5 and various OS updates by improving memory handling. Red Hat has also released security advisories for multiple versions of Enterprise Linux.
Affected products
- Apple iOS Before 26.5
- Apple iPadOS Before 26.5
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple visionOS Before 26.5
- Apple Safari Before 26.5
- Red Hat Enterprise Linux 7, 8, 9
Timeline
- 2026-05-11: disclosed
- 2026-05-11: advisory
- 2026-06-29: other: Red Hat enrichment and advisory updates