Description
A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Published: 2026-06-29
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a double‑free bug that was mitigated by enhancing memory management. Processing maliciously crafted web content may still trigger the double free, leading to an unexpected process crash. The crash causes denial of service but does not allow the attacker to execute arbitrary code or gain elevated privileges.

Affected Systems

Apple devices running iOS, iPadOS, macOS, tvOS, visionOS, or watchOS versions older than the releases listed in the advisory remain vulnerable. The patched releases are iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% shows a low likelihood of exploitation at this time, and the issue is not listed in the CISA KEV catalog. Remote exploitation would involve delivering malicious web content that triggers the double free, causing the affected process to crash. The flaw does not provide code execution or privilege escalation capabilities.

Generated by OpenCVE AI on August 4, 2026 at 08:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest software updates from Apple, including iOS 26.5.2, iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
  • If a patch cannot be applied immediately, block or carefully vet web content from untrusted or unknown sources, and consider limiting exposure through network or content filtering.
  • Configure automatic updates in system settings to receive future security patches promptly.
  • Monitor system logs for unexpected crash events that may indicate an attempted exploitation and investigate any abnormal application exits.

Generated by OpenCVE AI on August 4, 2026 at 08:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Double‑Free Bug Causing Web Content Crash on Apple Devices

Fri, 31 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Double free causes unexpected process crash in Apple OS 26.5.2

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash. A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
References

Tue, 30 Jun 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Tue, 30 Jun 2026 02:00:00 +0000

Type Values Removed Values Added
Title Double free causes unexpected process crash in Apple OS 26.5.2

Tue, 30 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Title Double Free in Memory Management Causing Process Crash on iOS and macOS
Weaknesses CWE-416

Mon, 29 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-415
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 22:15:00 +0000

Type Values Removed Values Added
Title Double Free in Memory Management Causing Process Crash on iOS and macOS
Weaknesses CWE-416

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-27T20:14:07.533Z

Reserved: 2026-05-01T22:46:21.644Z

Link: CVE-2026-43706

cve-icon Vulnrichment

Updated: 2026-06-29T21:44:40.827Z

cve-icon NVD

Status : Modified

Published: 2026-06-29T20:17:35.570

Modified: 2026-07-27T21:16:54.400

Link: CVE-2026-43706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T08:30:05Z

Weaknesses