Junglewise Threat Intelligence

CVE-2026-43725: Apple Safari and OS sandbox escape via improper input validation

CVE-2026-43725 · Severity: info · Published 2026-06-29

Technologies: Apple macOS, Apple Safari, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability in Apple's Safari browser and operating systems could allow a malicious website to bypass security protections. This could result in the website accessing restricted data or performing actions outside of its intended secure environment. Users should update to the latest software versions to protect their devices and data.

Technical details

An input validation issue in Apple's web processing components allowed for a sandbox escape. A malicious website could exploit this flaw to process restricted web content outside the intended security boundaries. The vulnerability affects Safari, iOS, iPadOS, and macOS Tahoe. Apple has addressed the issue by improving input validation in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2. Exploitation requires a user to visit a specially crafted malicious website.

Affected products

  • Apple Safari before 26.5.2
  • Apple iOS and iPadOS before 26.5.2
  • Apple macOS Tahoe before 26.5.2

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: advisory

References

Related threats