Executive brief
A vulnerability in Apple's Safari web browser and operating systems could allow a maliciously crafted website to cause the browser to crash. This affects users on iPhone, iPad, and Mac who visit untrusted web content. While primarily a stability issue, it can disrupt operations and user productivity.
Technical details
A stack overflow vulnerability exists in Apple Safari, iOS, iPadOS, and macOS Tahoe due to insufficient input validation when processing web content. An attacker can exploit this by enticing a user to visit a maliciously crafted webpage, leading to a denial-of-service (DoS) condition via a browser crash. The issue was addressed by improving input validation in the affected components. Patches are available in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.
Affected products
- Apple Safari < 26.5.2
- Apple iOS and iPadOS < 26.5.2
- Apple macOS Tahoe < 26.5.2
Timeline
- 2026-06-29: disclosed
- 2026-06-29: patched
- 2026-06-29: advisory