Junglewise Threat Intelligence

CVE-2026-28942: Apple Safari and OS use-after-free in memory management

CVE-2026-28942 · Severity: medium · CVSS 6.5 · Published 2026-05-11

Technologies: Apple Tvos, Apple macOS, Apple Safari, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS, Red Hat Enterprise Linux. Vendors: Apple, Red Hat.

Executive brief

A memory management vulnerability exists in Apple's Safari web browser and various operating systems including iOS and macOS. An attacker could exploit this by tricking a user into visiting a malicious website, which may cause the browser or device to crash unexpectedly. This could disrupt operations and lead to a temporary loss of service for affected users.

Technical details

A use-after-free (UAF) vulnerability (CWE-416) was identified in Apple's web processing components. The issue stems from improper memory management when handling web content, which can be triggered by a remote, unauthenticated attacker if a user visits a specially crafted webpage. While the primary reported impact is an unexpected application crash (denial of service), UAF vulnerabilities can sometimes be leveraged for more complex exploitation. Apple has addressed this issue in Safari 26.5 and corresponding OS updates (iOS/iPadOS 26.5, macOS Tahoe 26.5) by improving memory management logic. Red Hat has also issued advisories for affected Enterprise Linux versions.

Affected products

  • Apple Safari 26.5
  • Apple iOS 26.5
  • Apple iPadOS 26.5
  • Apple macOS Tahoe 26.5
  • Apple tvOS 26.5
  • Apple visionOS 26.5
  • Apple watchOS 26.5
  • Red Hat Enterprise Linux 7, 8, 9

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched

References

Related threats