Executive brief
A vulnerability in Apple's web browser and operating systems could allow a malicious website to crash the application or device. This affects users browsing the web on iPhones, iPads, and Mac computers. If exploited, it could disrupt operations or lead to unexpected service outages for users interacting with malicious web content.
Technical details
An out-of-bounds access vulnerability exists in Apple's web processing components across Safari, iOS, iPadOS, and macOS. The issue stems from insufficient bounds checking when handling web content. A remote attacker can exploit this by enticing a user to visit a maliciously crafted website, leading to an unexpected process crash or potentially further memory corruption. Apple has addressed this issue by improving bounds checking in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.
Affected products
- Apple Safari Before 26.5.2
- Apple iOS and iPadOS Before 26.5.2
- Apple macOS Tahoe Before 26.5.2
Timeline
- 2026-06-29: disclosed
- 2026-06-29: patched