Junglewise Threat Intelligence

CVE-2026-28947: Apple Safari and OS use-after-free in memory management

CVE-2026-28947 · Severity: high · CVSS 8.8 · Published 2026-05-11

Technologies: Apple Tvos, Apple macOS, Apple Safari, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability has been identified in Apple's Safari web browser and various operating systems including iOS and macOS. This flaw allows a malicious website to potentially crash the browser or execute unauthorized actions when a user visits a specially crafted page. Exploitation could lead to the theft of sensitive user data or a complete compromise of the device's security.

Technical details

A use-after-free vulnerability exists in Apple's Safari browser and the underlying web processing components of iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue stems from improper memory management when handling web content. A remote attacker can exploit this by enticing a user to visit a maliciously crafted website (UI:R). Successful exploitation can lead to arbitrary code execution or an unexpected application crash. The vulnerability was addressed by improving memory management in version 26.5 of the affected platforms.

Affected products

  • Apple Safari before 26.5
  • Apple iOS before 26.5
  • Apple iPadOS before 26.5
  • Apple macOS Tahoe before 26.5
  • Apple tvOS before 26.5
  • Apple visionOS before 26.5
  • Apple watchOS before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched: Fixed in Safari 26.5 and related OS updates.

References

Related threats