Executive brief
Apple Safari and various Apple operating systems are affected by a memory handling vulnerability. An attacker could use specially crafted web content to cause the browser to crash or potentially perform unauthorized actions. This impacts the stability of the device and the security of user data during web browsing.
Technical details
A memory handling vulnerability exists in Apple's WebKit-based products, including Safari and various operating systems. The flaw, identified as a buffer overflow or improper memory restriction (CWE-119/CWE-120), is triggered when the system processes maliciously crafted web content. A remote attacker can exploit this by enticing a user to visit a specially crafted website, leading to an unexpected application crash or potentially broader memory corruption. Apple has addressed the issue with improved memory handling in version 26.5 across its product lines. Red Hat has also identified impact in various Enterprise Linux versions that may utilize affected components.
Affected products
- Apple Safari before 26.5
- Apple iOS before 26.5
- Apple iPadOS before 26.5
- Apple macOS Tahoe before 26.5
- Apple tvOS before 26.5
- Apple visionOS before 26.5
- Apple watchOS before 26.5
- Red Hat Enterprise Linux 7, 8, 9
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched