Executive brief
A memory management vulnerability exists in Apple's Safari web browser and the operating systems for iPhone, iPad, and Mac. If a user visits a website containing specially crafted malicious content, the browser may crash unexpectedly. This could disrupt operations or potentially be used as a stepping stone for further unauthorized activity on the device.
Technical details
A use-after-free vulnerability exists in the memory management component of Safari and its underlying operating systems (iOS, iPadOS, and macOS). The flaw is triggered when the browser processes maliciously crafted web content, leading to memory corruption. An attacker can exploit this by enticing a user to visit a malicious webpage, potentially resulting in an unexpected application crash or arbitrary code execution. Apple has addressed this issue by improving memory management in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.
Affected products
- Apple Safari < 26.5.2
- Apple iOS and iPadOS < 26.5.2
- Apple macOS Tahoe < 26.5.2
Timeline
- 2026-06-29: disclosed
- 2026-06-29: patched