Executive brief
A memory management vulnerability exists in Apple's Safari web browser and the operating systems for iPhone, iPad, and Mac. If a user visits a website containing specially crafted malicious content, the browser may crash unexpectedly. This could disrupt operations or potentially be used as a stepping stone for further unauthorized activity on the device.
Technical details
A use-after-free vulnerability was identified in Apple's web processing components across multiple platforms. The flaw stems from improper memory management when handling web content, which can be triggered by a remote attacker via a maliciously crafted webpage. While the primary reported impact is an unexpected Safari crash (denial of service), use-after-free vulnerabilities often provide a primitive for arbitrary code execution. The issue was addressed by improving memory management in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.
Affected products
- Apple Safari < 26.5.2
- Apple iOS and iPadOS < 26.5.2
- Apple macOS Tahoe < 26.5.2
Timeline
- 2026-06-29: disclosed
- 2026-06-29: patched
- 2026-06-29: advisory