Description
A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Published: 2026-06-29
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A memory corruption flaw was found in the web rendering components of Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS. The issue was mitigated by improving memory handling, but prior to the fix, maliciously crafted web content could trigger it and lead to an unexpected process crash. This defect is a classic buffer overflow identified as CWE‑119, disrupting browsing and Web‑dependent functions.

Affected Systems

Apple Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS are vulnerable when running versions prior to 26.5.2 (Safari, iOS, iPadOS, macOS Tahoe) or 26.6 (tvOS, visionOS, watchOS). The bug has been fixed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, suggesting no known active exploitation. A potential attacker can cause a crash by directing a user to maliciously crafted web content, but no confirmed exploits are documented. With a CVSS score of 6.5, the vulnerability is considered medium severity, though the crash capability indicates a significant impact on availability.

Generated by OpenCVE AI on August 3, 2026 at 07:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS to the respective patched versions (26.5.2 or 26.6).
  • If an update cannot be performed immediately, limit user exposure to untrusted websites by using content filtering or disabling JavaScript for high‑risk sites.
  • Monitor Apple’s support site for additional patches or work‑arounds until the full update is deployed.

Generated by OpenCVE AI on August 3, 2026 at 07:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6398-1 webkit2gtk security update
History

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash. A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
References

Fri, 17 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 30 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Title Safari, iOS, iPadOS, and macOS Memory Corruption Crash Vulnerability

Tue, 30 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari

Mon, 29 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Title Safari, iOS, iPadOS, and macOS Memory Corruption Crash Vulnerability
Weaknesses CWE-119

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash.
References

Subscriptions

Apple Ios And Ipados Macos Safari
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-27T20:13:47.101Z

Reserved: 2026-05-01T22:46:21.644Z

Link: CVE-2026-43707

cve-icon Vulnrichment

Updated: 2026-06-30T14:25:47.612Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-10T00:00:00Z

Links: CVE-2026-43707 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T07:15:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer