Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Published: 2026-06-29
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash. Because the flaw does not enable remote code execution or data exfiltration, its primary consequence is a denial of service from terminating renderer or related processes.

Affected Systems

The vulnerability affects Apple Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS. Versions prior to Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6 are susceptible. The fix is incorporated in the mentioned versions and later.

Risk and Exploitability

The EPSS score is less than 1 percent and the vulnerability is not listed in CISA’s KEV catalog, indicating no widespread exploitation is currently known. The likely attack vector is via malicious web content rendered by Safari or other affected Apple operating systems, requiring the victim to load a crafted page. The CVSS score of 6.5 reflects a moderate severity: the flaw does not grant code execution but can crash processes, leading to a disruptive denial of service. Updating to the patched versions mitigates the risk.

Generated by OpenCVE AI on August 4, 2026 at 08:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Apple Safari to version 26.5.2 or later.
  • Upgrade iOS, iPadOS, macOS Tahoe to version 26.5.2 or later.
  • Upgrade tvOS, visionOS, and watchOS to version 26.6 or later.
  • Enable automatic system updates or regularly check Apple security advisories for new patches.

Generated by OpenCVE AI on August 4, 2026 at 08:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free Leading to Safari Web Process Crash

Fri, 31 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free Leading to Safari Web Process Crash

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash. A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
References

Tue, 30 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari

Tue, 30 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Leading to Process Crash in Safari, iOS, iPadOS and macOS

Mon, 29 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Leading to Process Crash in Safari, iOS, iPadOS and macOS
Weaknesses CWE-416

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Safari
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-27T20:12:57.800Z

Reserved: 2026-05-01T22:46:21.644Z

Link: CVE-2026-43709

cve-icon Vulnrichment

Updated: 2026-06-29T21:26:00.528Z

cve-icon NVD

Status : Modified

Published: 2026-06-29T20:17:35.887

Modified: 2026-07-27T21:16:54.867

Link: CVE-2026-43709

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T08:30:05Z

Weaknesses