Junglewise Threat Intelligence

CVE-2026-39872: Apple Safari and OSs memory handling vulnerability in Web Content

CVE-2026-39872 · Severity: info · Published 2026-06-29

Technologies: Apple macOS, Apple Safari, Apple iPadOS. Vendors: Apple.

Executive brief

Apple Safari, iOS, and macOS are affected by a memory handling vulnerability when processing web content. An attacker could use a specially crafted website to cause the browser or operating system to crash unexpectedly. This could lead to service disruptions for users browsing the web on affected Apple devices.

Technical details

A memory handling vulnerability exists in Apple's Safari browser and underlying operating systems (iOS, iPadOS, and macOS). The flaw is triggered when the system processes maliciously crafted web content, suggesting a root cause in the WebKit engine or related media handling components. An attacker can exploit this by enticing a user to visit a malicious webpage, resulting in an unexpected process crash (Denial of Service). Apple has addressed the issue with improved memory handling in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.

Affected products

  • Apple Safari Before 26.5.2
  • Apple iOS and iPadOS Before 26.5.2
  • Apple macOS Tahoe Before 26.5.2

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: patched

References

Related threats