Junglewise Threat Intelligence

CVE-2026-43804: Apple Safari and OSs denial of service via website visit

CVE-2026-43804 · Severity: info · CVSS 4.3 · Published 2026-07-27

Technologies: Apple macOS, Apple Safari, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability in Apple's web browser and operating systems could allow a malicious website to crash an application. This results in a denial-of-service, potentially disrupting user activities and device stability. Users are advised to update their Apple devices to the latest software versions to resolve this issue.

Technical details

A denial-of-service vulnerability exists in Apple Safari, iOS, iPadOS, macOS, and visionOS due to a state management issue. An attacker can exploit this by tricking a user into visiting a specially crafted website. Successful exploitation leads to an application-level denial-of-service (DoS). The issue was addressed through improved state management in Safari 26.6, iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, and visionOS 26.6.

Affected products

  • Apple Safari before 26.6
  • Apple iOS and iPadOS before 26.6
  • Apple macOS Tahoe before 26.6
  • Apple visionOS before 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats