Junglewise Threat Intelligence

CVE-2026-43746: Apple Safari and OS use-after-free in web content processing

CVE-2026-43746 · Severity: info · Published 2026-06-29

Technologies: Apple macOS, Apple Safari, Apple iPadOS. Vendors: Apple.

Executive brief

Apple has released security updates for Safari, iOS, iPadOS, and macOS to address a memory management vulnerability. An attacker could exploit this by tricking a user into visiting a malicious website, which may cause the browser or device to crash unexpectedly. This could disrupt operations or potentially be used as a stepping stone for further unauthorized activity.

Technical details

A use-after-free vulnerability exists in Apple's Safari browser and the underlying operating systems (iOS, iPadOS, and macOS Tahoe) when processing web content. The issue stems from improper memory management during the handling of maliciously crafted web content. A remote attacker can trigger this vulnerability by enticing a user to visit a specially crafted webpage. Successful exploitation primarily leads to an unexpected application crash (denial of service), though use-after-free bugs can sometimes be leveraged for arbitrary code execution. The issue was addressed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2 by improving memory management.

Affected products

  • Apple Safari Before 26.5.2
  • Apple iOS and iPadOS Before 26.5.2
  • Apple macOS Tahoe Before 26.5.2

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: patched

References

Related threats