Executive brief
A memory management vulnerability exists in Apple's Safari web browser and various operating systems including iOS and macOS. If a user visits a website containing specially crafted malicious content, it could cause the browser to crash unexpectedly. This issue primarily impacts the stability and reliability of the web browsing experience on Apple devices.
Technical details
A use-after-free vulnerability was identified in Apple's WebKit-based products, including Safari and the underlying web engines in iOS, iPadOS, macOS, visionOS, and watchOS. The flaw stems from improper memory management when processing web content. An attacker can exploit this by hosting a malicious website; when a user visits the site, the crafted content triggers the memory corruption. While the primary reported impact is an unexpected application crash (denial of service), use-after-free vulnerabilities can sometimes be leveraged for arbitrary code execution. The issue was addressed in version 26.6 of the affected platforms through improved memory management.
Affected products
- Apple Safari Before 26.6
- Apple iOS and iPadOS Before 26.6
- Apple macOS Tahoe Before 26.6
- Apple visionOS Before 26.6
- Apple watchOS Before 26.6
Timeline
- 2026-07-27: advisory: Initial advisory published by Apple and NVD.
- 2026-07-27: patched: Fixed in Safari 26.6 and related OS updates.