Junglewise Threat Intelligence

CVE-2026-28946: Apple Safari and macOS Tahoe use-after-free in Web Content processing

CVE-2026-28946 · Severity: medium · CVSS 6.5 · Published 2026-05-11

Technologies: Apple macOS, Apple Safari, Red Hat Enterprise Linux. Vendors: Apple, Red Hat.

Executive brief

Apple Safari and macOS Tahoe are affected by a memory management vulnerability that can be triggered when viewing malicious websites. An attacker could use this flaw to cause the web browser to crash unexpectedly, potentially disrupting user activity or service availability. Users should update to the latest versions of Safari and macOS to resolve this issue.

Technical details

A use-after-free vulnerability (CWE-416) exists in Apple Safari and macOS Tahoe due to improper memory management when processing web content. The issue can be triggered remotely if a user visits a maliciously crafted website (Network vector, User Interaction required). Successful exploitation primarily results in an application crash, leading to a denial-of-service condition. Apple has addressed this issue in Safari 26.5 and macOS Tahoe 26.5 by improving memory management logic. Red Hat has also identified related impacts across several Enterprise Linux versions.

Affected products

  • Apple Safari before 26.5
  • Apple macOS Tahoe before 26.5
  • Red Hat Enterprise Linux 7, 8, 9

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: advisory

References

Related threats