Junglewise Threat Intelligence

CVE-2026-28953: Apple and Red Hat memory corruption in web content processing

CVE-2026-28953 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Apple Tvos, Apple macOS, Apple Safari, Apple watchOS, Apple Visionos, Apple iPadOS, Red Hat Enterprise Linux. Vendors: Apple, Red Hat.

Executive brief

A memory handling vulnerability exists in several Apple operating systems and the Safari web browser. If a user visits a website containing specially crafted malicious content, it could cause the device's web processing component to crash or potentially allow unauthorized access to information. This affects iPhones, iPads, Macs, and other Apple devices, as well as some Red Hat Enterprise Linux systems.

Technical details

This vulnerability is classified as a memory corruption issue (CWE-119/CWE-120) resulting from improper memory handling when processing web content. The flaw exists in the core web processing components of Apple's ecosystem (Safari, iOS, macOS, etc.) and has also been identified in Red Hat Enterprise Linux environments. An unauthenticated remote attacker can exploit this by enticing a user to process maliciously crafted web content, which may lead to an unexpected process crash or arbitrary code execution. Apple addressed the issue with improved memory handling in their latest software updates.

Affected products

  • Apple iOS 18.7.9, 26.5
  • Apple iPadOS 18.7.9, 26.5
  • Apple macOS Tahoe 26.5
  • Apple Safari 26.5
  • Apple tvOS 26.5
  • Apple visionOS 26.5
  • Apple watchOS 26.5
  • Red Hat Enterprise Linux 7, 8, 9

Timeline

  • 2026-05-11: advisory: Initial disclosure date

References

Related threats