Junglewise Threat Intelligence

CVE-2026-43720: Apple Safari and OSs use-after-free in memory management

CVE-2026-43720 · Severity: info · Published 2026-06-29

Technologies: Apple Safari, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A memory management vulnerability exists in Apple's Safari web browser and the operating systems for iPhone, iPad, and Mac. If a user visits a website containing specially crafted malicious content, the browser may crash unexpectedly. This could disrupt operations or potentially be used as a stepping stone for further unauthorized activity on the device.

Technical details

A use-after-free vulnerability was identified in Apple's web processing components across multiple platforms. The flaw stems from improper memory management when handling web content, which can be triggered by a remote attacker via a maliciously crafted webpage. While the primary reported impact is an unexpected Safari crash (denial of service), use-after-free vulnerabilities often provide a primitive for arbitrary code execution. The issue was addressed by improving memory management in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.

Affected products

  • Apple Safari < 26.5.2
  • Apple iOS and iPadOS < 26.5.2
  • Apple macOS Tahoe < 26.5.2

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: patched
  • 2026-06-29: advisory

References

Related threats