Executive brief
Apple Safari and the operating systems for iPhone, iPad, and Mac are affected by a security flaw that can cause the web browser to crash. This occurs when the software processes specifically crafted, malicious web content. While primarily impacting stability, such issues can sometimes be used as a starting point for more complex attacks or to disrupt user operations.
Technical details
An out-of-bounds access vulnerability exists in Apple Safari, iOS, iPadOS, and macOS Tahoe due to insufficient bounds checking when processing web content. An attacker can exploit this by enticing a user to visit a maliciously crafted website or view malicious web content. Successful exploitation typically results in an unexpected application crash (denial of service). The issue was addressed by implementing improved bounds checking in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.
Affected products
- Apple Safari before 26.5.2
- Apple iOS and iPadOS before 26.5.2
- Apple macOS Tahoe before 26.5.2
Timeline
- 2026-06-29: disclosed
- 2026-06-29: patched