Executive brief
Apple has released security updates for Safari, iOS, iPadOS, and macOS to address a memory handling issue. If a user visits a website containing specially crafted malicious content, it could cause the web browser or the device's operating system to crash unexpectedly. This could disrupt business operations or lead to a temporary loss of service on affected Apple devices.
Technical details
A memory handling vulnerability exists in Apple's web content processing engine (WebKit) across multiple platforms. The flaw is triggered when the system processes maliciously crafted web content, which can lead to an unexpected process crash. This suggests a memory corruption or management issue that can be exploited remotely via a network vector (e.g., a malicious website) without requiring prior authentication. Apple has addressed the issue by improving memory handling in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.
Affected products
- Apple Safari < 26.5.2
- Apple iOS and iPadOS < 26.5.2
- Apple macOS Tahoe < 26.5.2
Timeline
- 2026-06-29: disclosed
- 2026-06-29: patched