Executive brief
Apple has released security updates for iOS, macOS, and other platforms to address a memory handling issue. If a user visits a website or views content specifically designed by an attacker, it could cause the application or system to crash unexpectedly. This could disrupt operations or lead to a temporary loss of service on the affected device.
Technical details
A memory corruption vulnerability exists in multiple Apple operating systems and the Safari browser due to improper memory handling when processing web content. An attacker can exploit this by enticing a user to process maliciously crafted web content, which may lead to an unexpected process crash or denial-of-service. The issue was addressed through improved memory handling in the affected components. Patches are available in iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5, and Safari 26.5.
Affected products
- Apple iOS Before 26.5
- Apple iPadOS Before 26.5
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple watchOS Before 26.5
- Apple Safari Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory