Executive brief
Apple has released security updates for Safari and various operating systems to address a vulnerability that could cause the web browser to crash. This issue occurs when the software processes specially crafted web content, potentially disrupting user activity or causing the application to become unresponsive. Users are advised to update their devices to the latest versions to maintain stability and security.
Technical details
An out-of-bounds access vulnerability exists in Safari and the underlying web-processing components of iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue stems from insufficient bounds checking when processing web content. A remote attacker can exploit this by enticing a user to visit a maliciously crafted website, leading to an application crash (denial of service). Apple addressed the root cause by improving bounds checking in Safari 26.6 and the corresponding OS updates.
Affected products
- Apple Safari before 26.6
- Apple iOS and iPadOS before 26.6
- Apple macOS Tahoe before 26.6
- Apple tvOS before 26.6
- Apple visionOS before 26.6
- Apple watchOS before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched