Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Published: 2026-06-29
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates from a memory handling flaw in Apple’s operating systems that can be triggered by maliciously crafted web content. When the flaw is exercised, an unexpected process crash occurs, leading to a denial of service on the affected device. The flaw does not grant privilege escalation or remote code execution; its effect is limited to availability loss.

Affected Systems

The vulnerability affects Apple iOS, iPadOS, macOS (Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.5.2), tvOS 26.6, visionOS 26.6, and watchOS 26.6. Versions prior to these patches are vulnerable.

Risk and Exploitability

The CVSS score reported is 6.5, which denotes a medium severity. The EPSS score is reported as < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA KEV. The flaw can be triggered by loading malicious web content through a browser or any web-enabled application, which is a likely attack vector. Because the impact is only an application crash and no control‑flow takeover is possible, the risk is moderate and primarily an availability threat for single devices, with exploitation being relatively straightforward in a user‑directed attack.

Generated by OpenCVE AI on August 3, 2026 at 07:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to iOS 26.5.2 or later
  • Upgrade to iPadOS 26.5.2 or later
  • Upgrade to macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, or macOS Tahoe 26.5.2 or later
  • Upgrade to tvOS 26.6, visionOS 26.6, or watchOS 26.6 or later

Generated by OpenCVE AI on August 3, 2026 at 07:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Memory Handling Bug Causing Process Crashes via Malicious Web Content

Fri, 31 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Memory Handling Bug Causes Unexpected Process Crash in Apple iOS, iPadOS, and macOS

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash. The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
References

Tue, 30 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Tue, 30 Jun 2026 02:00:00 +0000

Type Values Removed Values Added
Title Memory Handling Bug Causes Unexpected Process Crash in Apple iOS, iPadOS, and macOS

Tue, 30 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Title Browser Content Handling Crash in iOS, iPadOS, and macOS
Weaknesses CWE-119

Mon, 29 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-787
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Title Browser Content Handling Crash in iOS, iPadOS, and macOS
Weaknesses CWE-119

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash.
References

Subscriptions

Apple Ios And Ipados Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-27T20:12:08.874Z

Reserved: 2026-05-01T22:46:21.643Z

Link: CVE-2026-43703

cve-icon Vulnrichment

Updated: 2026-06-29T21:41:49.276Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T07:15:04Z

Weaknesses