Executive brief
A memory management vulnerability exists in Apple's Safari web browser and various operating systems including iOS and macOS. If a user visits a website containing specially crafted malicious content, it could cause the browser to crash unexpectedly. This issue impacts the stability of the device and could potentially be used as a stepping stone for further unauthorized activity.
Technical details
A use-after-free vulnerability was identified in Apple's web processing components across Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The flaw is triggered when the engine processes maliciously crafted web content, leading to memory corruption. An attacker could exploit this by hosting a malicious website that, when visited by a user, causes a denial-of-service (crash). The issue was addressed through improved memory management in version 26.6 of the affected products.
Affected products
- Apple Safari before 26.6
- Apple iOS and iPadOS before 26.6
- Apple macOS Tahoe before 26.6
- Apple tvOS before 26.6
- Apple visionOS before 26.6
- Apple watchOS before 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: patched