Executive brief
Apple has released security updates for iPhone, iPad, and Mac to address a memory handling issue. If a user visits a website containing specially crafted malicious content, it could cause the web browser or associated system processes to crash unexpectedly. This primarily impacts the reliability and availability of the device's web-related services.
Technical details
A memory handling vulnerability exists in Apple's operating systems (iOS, iPadOS, and macOS) when processing web content. The root cause is improper memory management, which can be triggered by a remote attacker who entices a user to visit a maliciously crafted webpage. Successful exploitation results in a denial-of-service (DoS) condition via an unexpected process crash. Apple has addressed this issue with improved memory handling in iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.
Affected products
- Apple iOS and iPadOS < 26.5.2
- Apple macOS Tahoe < 26.5.2
Timeline
- 2026-06-29: disclosed
- 2026-06-29: patched