Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
Published: 2026-05-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper memory handling flaw in Apple’s Safari browser and several operating systems causes the parser that renders web content to crash when it receives maliciously crafted data. The vulnerability results in the termination of the affected process, effectively denying service to users who rely on Safari or the underlying system processes. The weakness is a buffer overflow condition (CWE-119 and CWE-120).

Affected Systems

The flaw affects Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. It is fixed in Safari 26.5, iOS 18.7.9 and 26.5, iPadOS 18.7.9 and 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5; all earlier releases remain vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score of <1 % suggests a very low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog and no public exploit has been documented. Based on the description, it is inferred that an attacker could deliver maliciously crafted web pages that the victim’s device loads, triggering the crash; therefore the risk is moderate but can be fully mitigated by applying the available updates.

Generated by OpenCVE AI on June 3, 2026 at 04:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest updates for all Apple devices, including Safari 26.5, iOS 18.7.9/26.5, iPadOS 18.7.9/26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5.
  • Configure devices to automatically install future security releases to prevent similar gaps.
  • Implement web‑content filtering or proxy rules to block known malicious sites until the updates are applied, especially in environments where users may access untrusted content.

Generated by OpenCVE AI on June 3, 2026 at 04:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Title webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
Weaknesses CWE-120
References
Metrics threat_severity

None

threat_severity

Important


Fri, 22 May 2026 17:30:00 +0000

Type Values Removed Values Added
Title Improper Memory Handling Triggering Process Crashes in Safari and Apple OSes

Fri, 22 May 2026 13:30:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 14 May 2026 01:30:00 +0000

Type Values Removed Values Added
Title Improper Memory Handling Triggering Process Crashes in Safari and Apple OSes

Wed, 13 May 2026 23:00:00 +0000

Type Values Removed Values Added
Title Malicious Web Content Crash Vulnerability
Weaknesses CWE-416
CWE-674

Wed, 13 May 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash. The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
References

Wed, 13 May 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 12 May 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 11 May 2026 22:30:00 +0000

Type Values Removed Values Added
Title Malicious Web Content Crash Vulnerability
Weaknesses CWE-416
CWE-674

Mon, 11 May 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 11 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-05-22T12:54:42.181Z

Reserved: 2026-03-03T16:36:03.990Z

Link: CVE-2026-28955

cve-icon Vulnrichment

Updated: 2026-05-12T19:51:56.656Z

cve-icon NVD

Status : Modified

Published: 2026-05-11T21:18:56.570

Modified: 2026-05-22T14:16:25.250

Link: CVE-2026-28955

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-02T00:00:00Z

Links: CVE-2026-28955 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-03T04:15:24Z

Weaknesses