Executive brief
A security vulnerability in Apple's Safari web browser and operating systems (iOS, iPadOS, and macOS) could allow a malicious website to crash the browser or device. This occurs when the system processes specifically crafted web content. Users are advised to update their devices to the latest software versions to prevent potential stability issues or unauthorized code execution.
Technical details
A memory corruption vulnerability exists in Apple's web processing components across Safari, iOS, iPadOS, and macOS Tahoe. The flaw is rooted in improper memory handling when parsing or rendering maliciously crafted web content. An attacker can exploit this by enticing a user to visit a specially designed webpage, potentially leading to an unexpected process crash or arbitrary code execution. Apple addressed the issue by improving memory handling in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.
Affected products
- Apple Safari Before 26.5.2
- Apple iOS and iPadOS Before 26.5.2
- Apple macOS Tahoe Before 26.5.2
Timeline
- 2026-06-29: disclosed
- 2026-06-29: patched