Executive brief
A vulnerability exists in Apple's web processing engine across multiple devices, including iPhones, iPads, and Macs. If a user visits a specially crafted malicious website, it could cause the browser or system processes to crash. In some scenarios, this type of memory handling issue can lead to broader system instability or unauthorized access to information.
Technical details
A memory handling vulnerability (classified as CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer) exists in Apple's web content processing components. The flaw is triggered when the system processes maliciously crafted web content, which can lead to an unexpected process crash or memory corruption. The attack vector is remote via a network, requiring minimal user interaction (such as visiting a malicious website). Apple has addressed the issue with improved memory handling in Safari 26.5, iOS/iPadOS 18.7.9, and version 26.5 of iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS.
Affected products
- Apple Safari Before 26.5
- Apple iOS Before 18.7.9, and 26.x before 26.5
- Apple iPadOS Before 18.7.9, and 26.x before 26.5
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple visionOS Before 26.5
- Apple watchOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory