Junglewise Threat Intelligence

CVE-2026-43706: Apple iOS and macOS double free in web content processing

CVE-2026-43706 · Severity: info · Published 2026-06-29

Technologies: Apple macOS, Apple iPadOS. Vendors: Apple.

Executive brief

Apple has released security updates for iOS, iPadOS, and macOS to address a memory management vulnerability. An attacker could exploit this by tricking a user into viewing specially crafted web content, which may cause the device's browser or related processes to crash. While primarily described as a stability issue, such memory flaws can sometimes be leveraged for more complex attacks.

Technical details

A double free vulnerability exists in the memory management components of iOS, iPadOS, and macOS. The flaw is triggered when the system processes maliciously crafted web content, likely within the WebKit engine or associated media handling frameworks. An attacker can exploit this by hosting a malicious webpage or sending a link that, when opened by a user, triggers the memory corruption. This results in an unexpected process crash (Denial of Service). Apple addressed the issue by improving memory management logic in iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.

Affected products

  • Apple iOS and iPadOS before 26.5.2
  • Apple macOS Tahoe before 26.5.2

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: patched

References

Related threats