Junglewise Threat Intelligence

CVE-2026-43716: Apple Safari and OS memory handling vulnerability in Web Content

CVE-2026-43716 · Severity: info · Published 2026-06-29

Technologies: Apple macOS, Apple Safari, Apple iPadOS. Vendors: Apple.

Executive brief

Apple has released security updates for Safari, iOS, iPadOS, and macOS to address a memory handling issue. An attacker could exploit this by tricking a user into visiting a maliciously crafted website, which may cause the Safari browser to crash unexpectedly. This could disrupt user operations and impact the reliability of the web browser on affected devices.

Technical details

A memory handling vulnerability exists in Apple's web processing components across multiple platforms. The issue is triggered when Safari or the underlying OS components process maliciously crafted web content, potentially leading to a denial-of-service (DoS) via an unexpected application crash. The vulnerability was addressed by improving memory management logic. It affects Safari versions prior to 26.5.2, iOS and iPadOS versions prior to 26.5.2, and macOS Tahoe versions prior to 26.5.2. Attackers can reach this vulnerability remotely via the network without prior authentication, provided they can entice a user to load a malicious webpage.

Affected products

  • Apple Safari Before 26.5.2
  • Apple iOS and iPadOS Before 26.5.2
  • Apple macOS Tahoe Before 26.5.2

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: patched

References

Related threats