Junglewise Threat Intelligence

CVE-2026-43715: Apple Safari and OSs use-after-free in web content processing

CVE-2026-43715 · Severity: info · Published 2026-06-29

Technologies: Apple Safari, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A memory management vulnerability exists in Apple's web processing engine used by Safari, iOS, and macOS. If a user visits a website containing specially crafted malicious content, it could lead to memory corruption on their device. This could potentially allow an attacker to disrupt the device's operations or gain unauthorized access to data.

Technical details

A use-after-free vulnerability was identified in the way Apple's operating systems and Safari browser handle web content. The flaw stems from improper memory management during the processing of web-based data. An attacker can exploit this by enticing a user to visit a maliciously crafted webpage, triggering memory corruption. This could potentially lead to arbitrary code execution or a denial-of-service condition. Apple has addressed the issue by improving memory management in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.

Affected products

  • Apple Safari Before 26.5.2
  • Apple iOS and iPadOS Before 26.5.2
  • Apple macOS Tahoe Before 26.5.2

Timeline

  • 2026-06-29: advisory
  • 2026-06-29: patched

References

Related threats