Junglewise Threat Intelligence

CVE-2026-43704: Apple Safari and OSs use-after-free via malicious web extension

CVE-2026-43704 · Severity: info · Published 2026-06-29

Technologies: Apple Safari, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A memory management vulnerability exists in Apple's Safari browser and operating systems (iOS, iPadOS, and macOS). A malicious web extension could exploit this flaw to cause the browser or system processes to crash unexpectedly. This could disrupt user operations and impact the stability of the device.

Technical details

A use-after-free vulnerability was identified in Apple's memory management across multiple platforms. The flaw is triggered when a malicious web extension interacts with system memory in a way that references memory after it has been freed. This can lead to an unexpected process crash, potentially resulting in a denial-of-service condition for the affected application or component. The issue was addressed by improving memory management logic in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.

Affected products

  • Apple Safari < 26.5.2
  • Apple iOS and iPadOS < 26.5.2
  • Apple macOS Tahoe < 26.5.2

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: patched

References

Related threats