Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash.
Published: 2026-06-29
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is tied to the handling of memory in Apple’s web rendering engine. When Safari, iOS, iPadOS, or macOS receives maliciously crafted web content, the improved memory handling logic can be triggered in a way that causes an unexpected process crash. The crash does not directly expose code execution or data exfiltration, but it terminates the browser or web‑related process, disrupting user sessions and potentially rendering the device unusable until restarted. The nature of the weakness is consistent with improper memory management, such as a use‑after‑free or bad pointer dereference. The impact is limited to denial of service for the affected user or system.

Affected Systems

Apple’s Safari browser, iOS, iPadOS, and macOS Tahoe are affected when they run versions prior to 26.5.2. Apple states that the issue is fixed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2. No other Apple products or versions are mentioned.

Risk and Exploitability

The CVE lists no EPSS score and it is not catalogued in the CISA KEV list, suggesting that active exploitation is either not observed or not widespread at this time. With the known remediation, the risk is mitigated once the update is installed. Attackers would need a user or environment to load the malicious content; there are no indications of a network‑based or remote trigger. The crash is local to the browser or system process, so the attacker’s impact remains confined to denial of service on the infected device.

Generated by OpenCVE AI on June 29, 2026 at 21:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Safari patch to 26.5.2 or later
  • Update iOS, iPadOS, or macOS Tahoe to version 26.5.2 or later
  • Avoid opening untrusted or suspicious web pages until the patch is installed

Generated by OpenCVE AI on June 29, 2026 at 21:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 29 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-787
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Title Malicious Web Content Causing Process Crash in Safari, iOS, iPadOS, and macOS
Weaknesses CWE-416

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-06-29T21:29:27.255Z

Reserved: 2026-05-01T22:46:21.644Z

Link: CVE-2026-43712

cve-icon Vulnrichment

Updated: 2026-06-29T21:29:19.468Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-29T21:30:03Z

Weaknesses