Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
Published: 2026-05-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a flaw in the memory handling of the web content engine that can be triggered by maliciously crafted web pages. When such content is processed, the affected process may crash, leading to a denial‑of‑service condition for the user or application that relied on that process. This is a pure crash bug with no direct information disclosure or code execution reported.

Affected Systems

Apple iOS, iPadOS, macOS, tvOS and visionOS versions before 26.5 are vulnerable. The fix is delivered in iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5 and visionOS 26.5.

Risk and Exploitability

The exploit requires the attacker to deliver a specially crafted web page that the victim's browser or web engine will load. No authentication or privileges are required beyond normal browsing. The EPSS score is < 1% and the CVSS score is 7.5; the vulnerability is not listed in the CISA KEV catalog; nevertheless, the crash impact is significant enough that any device that processes untrusted web content could be brought to a denial-of-service state.

Generated by OpenCVE AI on May 12, 2026 at 16:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Apple operating‑system updates (iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5 or visionOS 26.5) on affected devices.
  • Disable or restrict access to untrusted web content by configuring web filters or safe browsing settings on the device or network.
  • If updates are unavailable for a device, avoid opening or rendering the suspect web pages until a patch can be applied.

Generated by OpenCVE AI on May 12, 2026 at 16:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 12 May 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 12 May 2026 16:45:00 +0000

Type Values Removed Values Added
Title Apple Web Content Engine Crash Leading to Denial of Service

Tue, 12 May 2026 15:45:00 +0000

Type Values Removed Values Added
Title Crash on Malicious Web Content Due to Improper Memory Handling
Weaknesses CWE-787

Tue, 12 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 11 May 2026 22:00:00 +0000

Type Values Removed Values Added
Title Crash on Malicious Web Content Due to Improper Memory Handling
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Weaknesses CWE-119
CWE-787
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos

Mon, 11 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-05-12T13:58:28.178Z

Reserved: 2026-03-03T16:36:03.984Z

Link: CVE-2026-28905

cve-icon Vulnrichment

Updated: 2026-05-12T13:57:53.330Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-11T21:18:53.310

Modified: 2026-05-12T17:51:21.570

Link: CVE-2026-28905

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T16:30:19Z

Weaknesses