Junglewise Threat Intelligence

CVE-2026-43740: Apple Safari and OSs memory disclosure via web content

CVE-2026-43740 · Severity: info · CVSS 0 · Published 2026-06-29

Technologies: Apple Safari, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Apple has released security updates for Safari, iOS, iPadOS, and macOS to address a vulnerability that could allow the disclosure of sensitive information. If a user visits a specially crafted website, the malicious content could potentially read data from the device's memory. This could lead to the exposure of private information handled by the web browser or operating system.

Technical details

A memory handling vulnerability exists in Apple's web processing components affecting Safari, iOS, iPadOS, and macOS. The flaw is triggered when the system processes maliciously crafted web content, leading to an out-of-bounds read or similar memory mismanagement that results in the disclosure of process memory. An attacker can exploit this by enticing a user to visit a malicious webpage. Apple has addressed the issue by improving memory handling in Safari 26.5.2, iOS/iPadOS 26.5.2, and macOS Tahoe 26.5.2.

Affected products

  • Apple Safari Before 26.5.2
  • Apple iOS and iPadOS Before 26.5.2
  • Apple macOS Tahoe Before 26.5.2

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: patched

References

Related threats