Junglewise Threat Intelligence

CVE-2026-28917: Apple Multiple Operating Systems Denial of Service via Web Content

CVE-2026-28917 · Severity: medium · CVSS 4.3 · Published 2026-05-11

Technologies: Apple Tvos, Apple macOS, Apple Safari, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Apple has released security updates for various operating systems and the Safari web browser to address a stability issue. If a user visits a website containing specifically crafted malicious content, it could cause the browser or associated system processes to crash unexpectedly. This primarily impacts the reliability and availability of the device's web-related services.

Technical details

A vulnerability exists in Apple's web content processing components across multiple platforms, including iOS, macOS, and Safari. The flaw is rooted in insufficient input validation when parsing maliciously crafted web content. An attacker can exploit this by hosting a specially crafted webpage; when a user visits the site, the processing of this content triggers an unexpected process crash, leading to a denial-of-service condition for the affected application or component. Apple addressed the issue by improving input validation logic in Safari 26.5, iOS/iPadOS 18.7.9, and version 26.5 of macOS Tahoe, tvOS, visionOS, and watchOS.

Affected products

  • Apple iOS Before 18.7.9, before 26.5
  • Apple iPadOS Before 18.7.9, before 26.5
  • Apple macOS Tahoe Before 26.5
  • Apple tvOS Before 26.5
  • Apple visionOS Before 26.5
  • Apple watchOS Before 26.5
  • Apple Safari Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats