Junglewise Threat Intelligence

CVE-2026-43663: Apple Safari and OSs memory corruption in web content processing

CVE-2026-43663 · Severity: info · Published 2026-06-29

Technologies: Apple Safari, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Apple has released security updates for Safari, iOS, iPadOS, and macOS to address a memory handling issue. If a user visits a website containing maliciously crafted content, the browser or system process may crash unexpectedly. This could lead to a temporary disruption of service or potentially be used as a stepping stone for further attacks.

Technical details

A memory handling vulnerability exists in Apple's web content processing engine affecting Safari, iOS, iPadOS, and macOS. The issue is triggered when the system processes maliciously crafted web content, which can lead to an unexpected process crash. This suggests a memory corruption or management flaw, such as a buffer overflow or use-after-free, though specific details are limited. An attacker can exploit this by enticing a user to visit a malicious website. The vulnerability was addressed with improved memory handling in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.

Affected products

  • Apple Safari < 26.5.2
  • Apple iOS and iPadOS < 26.5.2
  • Apple macOS Tahoe < 26.5.2

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: patched

References

Related threats