Executive brief
A vulnerability in Apple's web browser and operating systems could allow a malicious website to crash an application. This results in a denial-of-service, potentially disrupting user activities and device stability. Users are advised to update their Apple devices to the latest software versions to resolve this issue.
Technical details
A denial-of-service vulnerability exists in Apple Safari, iOS, iPadOS, macOS, and visionOS due to a state management issue. An attacker can exploit this by tricking a user into visiting a specially crafted website. Successful exploitation leads to an application-level denial-of-service (DoS). The issue was addressed through improved state management in Safari 26.6, iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, and visionOS 26.6.
Affected products
- Apple Safari before 26.6
- Apple iOS and iPadOS before 26.6
- Apple macOS Tahoe before 26.6
- Apple visionOS before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched