Junglewise Threat Intelligence

CVE-2026-43745: Apple Safari and OS out-of-bounds write in Web Content processing

CVE-2026-43745 · Severity: info · Published 2026-06-29

Technologies: Apple Safari, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A vulnerability in Apple's Safari web browser and operating systems could allow maliciously crafted web content to cause an unexpected application crash. This affects users browsing the web on iPhone, iPad, and Mac devices. Exploitation typically occurs when a user visits a compromised or malicious website, potentially disrupting operations or leading to further instability.

Technical details

An out-of-bounds write vulnerability exists in Apple Safari, iOS, iPadOS, and macOS Tahoe due to insufficient input validation when processing web content. An attacker can exploit this by hosting a malicious website or injecting crafted content into a legitimate one; when a user visits the site, the browser may experience memory corruption. While the primary reported impact is an unexpected Safari crash, out-of-bounds writes can often be leveraged for more complex memory corruption exploits. The issue was addressed by improving input validation in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.

Affected products

  • Apple Safari before 26.5.2
  • Apple iOS and iPadOS before 26.5.2
  • Apple macOS Tahoe before 26.5.2

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: advisory
  • 2026-06-29: patched

References

Related threats