Executive brief
A memory management vulnerability exists in Apple's web browser and operating systems. If a user visits a malicious website or views specially crafted web content, it could cause the application to crash unexpectedly. This could disrupt operations or potentially be used as a stepping stone for further unauthorized activity on the device.
Technical details
A use-after-free vulnerability was identified in Apple's memory management when processing web content. The flaw affects Safari, iOS, iPadOS, and macOS Tahoe. An attacker can exploit this by enticing a user to process maliciously crafted web content, typically via a network-based vector (e.g., a malicious website). Successful exploitation primarily results in an unexpected process crash, though use-after-free vulnerabilities can sometimes lead to arbitrary code execution. The issue was addressed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2 through improved memory management.
Affected products
- Apple Safari before 26.5.2
- Apple iOS and iPadOS before 26.5.2
- Apple macOS Tahoe before 26.5.2
Timeline
- 2026-06-29: disclosed
- 2026-06-29: patched