Junglewise Threat Intelligence

CVE-2026-43699: Apple Safari and OS use-after-free in Web Content processing

CVE-2026-43699 · Severity: info · Published 2026-06-29

Technologies: Apple Safari, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Apple Safari and operating systems (iOS, iPadOS, and macOS) are affected by a memory management vulnerability. If a user visits a malicious website, the browser or system process may crash unexpectedly. This could disrupt operations or be used as part of a more complex attack to compromise the device.

Technical details

A use-after-free vulnerability exists in Apple's web processing components across Safari, iOS, iPadOS, and macOS. The issue stems from improper memory management when processing web content. An attacker can exploit this by enticing a user to visit a maliciously crafted webpage, leading to an unexpected process crash or potentially arbitrary code execution. The vulnerability was addressed by improving memory management logic. Patches are available in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.

Affected products

  • Apple Safari before 26.5.2
  • Apple iOS and iPadOS before 26.5.2
  • Apple macOS Tahoe before 26.5.2

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: patched

References

Related threats