Executive brief
Safari is Apple's web browser used to access websites on iPhones, iPads, and Macs. Processing maliciously crafted web content can cause Safari to crash unexpectedly, interrupting user browsing and potentially affecting productivity. An attacker could exploit this by hosting a malicious website that triggers the crash when visited.
Technical details
A memory handling vulnerability in Safari's web content processing allows maliciously crafted web pages to trigger an unexpected application crash. The vulnerability was addressed through improved memory handling in Safari 26.5 and corresponding OS updates. The attack vector is network-based, requiring only that a user visit a malicious website; no authentication or user interaction beyond normal browsing is required. The impact is denial of service (application crash), not code execution or data disclosure. Patches are available in Safari 26.5, iOS 18.7.10, iPadOS 18.7.10, iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5.
Affected products
- Apple Safari before 26.5
- Apple iOS before 18.7.10 and before 26.5
- Apple iPadOS before 18.7.10 and before 26.5
- Apple macOS Tahoe before 26.5
- Apple tvOS before 26.5
- Apple visionOS before 26.5
- Apple watchOS before 26.5
Timeline
- 2026-08-17: disclosed: CVE-2026-28984 publicly disclosed
- 2026-05-11: patched: Patches released in Safari 26.5 and corresponding OS updates