Executive brief
A security vulnerability exists in Apple's Safari web browser and the operating systems for iPhone, iPad, and Mac. If a user visits a website containing specially crafted malicious content, it could cause the browser or the device's software to crash unexpectedly. This issue affects the stability of the device and could potentially be used to disrupt operations.
Technical details
A use-after-free vulnerability exists in Apple's web processing components across multiple platforms, including Safari, iOS, iPadOS, and macOS Tahoe. The flaw is rooted in improper memory management during the handling of web content. An attacker can exploit this by enticing a user to visit a maliciously crafted webpage, leading to an unexpected process crash or potentially arbitrary code execution. The issue was addressed by improving memory management in the affected components. Patches are available in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.
Affected products
- Apple Safari Before 26.5.2
- Apple iOS and iPadOS Before 26.5.2
- Apple macOS Tahoe Before 26.5.2
Timeline
- 2026-06-29: disclosed
- 2026-06-29: patched