Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
Published: 2026-05-11
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Apple’s web content rendering subsystem contains a memory handling flaw that can be triggered by maliciously crafted web pages. When the vulnerable code processes such content, it results in an unexpected process crash, effectively denying service to the affected application or system. This weakness is most closely associated with improper memory management weaknesses such as use‑after‑free or out‑of‑bounds memory accesses, categorised as CWE‑416. The crash itself does not disclose sensitive information, but it can enable an attacker to cause instability or to exhaust system resources through repeated crashes.

Affected Systems

The vulnerability affects multiple Apple operating systems. It is known to be fixed in iOS 18.7.9, iOS 26.5, iPadOS 18.7.9, iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5. Users running older, unpatched versions of any of these platforms are potentially exposed.

Risk and Exploitability

The exploit vector is inferred to be remote, leveraging crafted web content that a user might view in a browser, email client, or any other web‑enabled application. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that large‑scale exploitation is not confirmed. Nevertheless, because the flaw results in a crash and can be triggered by web traffic that may already be widespread, the risk is moderate. Without the official CVSS score, users should treat an unpatched system as at risk for service disruption and should prioritize applying the appropriate OS update.

Generated by OpenCVE AI on May 11, 2026 at 21:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest iOS, iPadOS, macOS, tvOS, visionOS, and watchOS updates that include the fix (e.g., iOS 18.7.9, iOS 26.5, etc.).
  • Subscribe to Apple’s security bulletin feeds to receive timely updates about new fixes and advisories.
  • If possible, restrict or sanitize remote web content in applications to prevent delivery of maliciously crafted pages until a patch is applied.

Generated by OpenCVE AI on May 11, 2026 at 21:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 11 May 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 11 May 2026 22:00:00 +0000

Type Values Removed Values Added
Title Malicious Web Content Processing Crash in Apple OS
Weaknesses CWE-416

Mon, 11 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-05-11T20:07:44.866Z

Reserved: 2026-03-03T16:36:03.983Z

Link: CVE-2026-28903

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-11T21:18:53.113

Modified: 2026-05-12T14:13:03.510

Link: CVE-2026-28903

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-11T22:15:06Z

Weaknesses