Junglewise Threat Intelligence

CVE-2026-43731: Apple Safari and OSs use-after-free in web content processing

CVE-2026-43731 · Severity: info · Published 2026-06-29

Technologies: Apple Safari, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Apple has released security updates for Safari, iOS, iPadOS, and macOS to address a memory management vulnerability. This flaw allows a malicious website to cause memory corruption on a user's device if they visit a specially crafted page. Successful exploitation could lead to unpredictable system behavior or unauthorized code execution, potentially compromising personal data or device stability.

Technical details

A use-after-free vulnerability exists in Apple's web processing components across Safari, iOS, iPadOS, and macOS Tahoe. The issue stems from improper memory management during the processing of web content. A remote attacker can exploit this by enticing a user to visit a maliciously crafted website, leading to memory corruption. This could potentially allow for arbitrary code execution within the context of the browser or operating system. Apple has addressed the root cause by improving memory management in the affected versions.

Affected products

  • Apple Safari < 26.5.2
  • Apple iOS and iPadOS < 26.5.2
  • Apple macOS Tahoe < 26.5.2

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: patched

References

Related threats