Junglewise Threat Intelligence

CVE-2026-28944: Apple OS memory corruption via malicious web content

CVE-2026-28944 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Apple macOS, Apple Iphone Os, Apple iPadOS, Apple Visionos, Apple Safari. Vendors: Apple.

Executive brief

Apple has released security updates for iOS, macOS, and Safari to address a memory handling issue. If a user visits a website containing specially crafted malicious content, it could cause the web browser or the underlying system process to crash unexpectedly. This primarily impacts the reliability and availability of the device, potentially disrupting work or causing data loss in open applications.

Technical details

A memory handling vulnerability exists in multiple Apple operating systems and the Safari browser when processing web content. The root cause is improper memory management during the parsing of maliciously crafted web content, which can trigger an unexpected process termination. An attacker can exploit this by enticing a user to visit a malicious webpage or view crafted content, leading to a denial-of-service (DoS) condition. Apple has addressed the issue by improving memory handling in iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, and Safari 26.5.

Affected products

  • Apple iOS Before 26.5
  • Apple iPadOS Before 26.5
  • Apple macOS Tahoe Before 26.5
  • Apple visionOS Before 26.5
  • Apple Safari Before 26.5

Timeline

  • 2026-05-11: advisory: Apple released security advisories for multiple products.
  • 2026-05-11: patched: Fixed in iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, and Safari 26.5.

References

Related threats