Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Published: 2026-08-17
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper memory handling in Safari, allowing maliciously crafted web content to trigger a crash. The crash results in a local denial‑of‑service condition for the user’s device. No evidence exists that the flaw enables code execution or network‑wide impact.

Affected Systems

Apple’s iOS and iPadOS platforms are affected, specifically devices running versions earlier than iOS 18.7.10 and iPadOS 18.7.10. The issue is resolved in those 18.7.10 releases.

Risk and Exploitability

The exploit is likely local, requiring a user to view or interact with harmful web content. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog. While the CVSS score is not provided, the denial‑of‑service impact and local nature suggest a moderate risk for affected users.

Generated by OpenCVE AI on August 17, 2026 at 22:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest iOS 18.7.10 or iPadOS 18.7.10 update that fixes the memory handling issue.
  • Update all affected devices to the latest publicly available iOS or iPadOS version if 18.7.10 is not yet available.
  • Configure device restrictions to limit contact with potentially malicious web content, such as enabling safe browsing features.

Generated by OpenCVE AI on August 17, 2026 at 22:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 17 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Safari Crash via Malicious Web Content Leading to Denial of Service
First Time appeared Apple
Apple ios And Ipados
Weaknesses CWE-416
Vendors & Products Apple
Apple ios And Ipados

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Subscriptions

Apple Ios And Ipados
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:30:37.215Z

Reserved: 2026-03-03T16:36:03.993Z

Link: CVE-2026-28984

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T22:17:04.010

Modified: 2026-08-17T22:17:04.010

Link: CVE-2026-28984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T22:30:04Z

Weaknesses