Executive brief
Apple has released security updates for Safari, iOS, iPadOS, and macOS to address a memory management flaw. An attacker could exploit this by tricking a user into visiting a specially crafted website, which may cause the Safari browser to crash unexpectedly. This could disrupt operations or potentially be used as a stepping stone for further malicious activity.
Technical details
A use-after-free vulnerability exists in Apple's web processing components across multiple platforms, including Safari, iOS, iPadOS, and macOS Tahoe. The issue stems from improper memory management when handling web content. A remote attacker can exploit this by enticing a user to process maliciously crafted web content, leading to an application crash (denial of service) or potentially arbitrary code execution. The vulnerability was addressed through improved memory management in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.
Affected products
- Apple Safari Before 26.5.2
- Apple iOS and iPadOS Before 26.5.2
- Apple macOS Tahoe Before 26.5.2
Timeline
- 2026-06-29: disclosed
- 2026-06-29: patched