Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash.
Published: 2026-06-29
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Apple’s Safari, iOS, iPadOS, and macOS Tahoe are affected by a memory handling flaw that can be triggered by maliciously crafted web content. When the vulnerable rendering engine processes such content, the improper memory management causes an unexpected crash of the browser or related system process. The crash does not give an attacker code execution or data exfiltration capabilities; it simply terminates the affected application, leading to loss of service for the user. The weakness maps to common improper memory management issues such as buffer overread, use‑after‑free, and bad pointer dereference.

Affected Systems

Versions of Safari, iOS, iPadOS, and macOS Tahoe older than 26.5.2 are impacted. An attacker can exploit the vulnerability on any device running a prior version of these products when a user visits or renders malicious web content.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate threat. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of widespread active exploitation at present. Attackers need to lure a user to a malicious page or otherwise load the problematic content; the exploit does not involve a network‑based remote trigger. Thus the principal risk remains localized denial of service on the compromised device.

Generated by OpenCVE AI on June 30, 2026 at 01:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Safari patch (version 26.5.2 or newer)
  • Upgrade iOS, iPadOS, or macOS Tahoe to version 26.5.2 or newer
  • Until the update is installed, refrain from opening suspected or untrusted web pages

Generated by OpenCVE AI on June 30, 2026 at 01:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Safari, iOS, and macOS Crash in Web Rendering Vulnerability webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 30 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari

Tue, 30 Jun 2026 02:00:00 +0000

Type Values Removed Values Added
Title Safari, iOS, and macOS Crash in Web Rendering Vulnerability

Tue, 30 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Title Malicious Web Content Causing Process Crash in Safari, iOS, iPadOS, and macOS
Weaknesses CWE-416

Mon, 29 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-787
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Title Malicious Web Content Causing Process Crash in Safari, iOS, iPadOS, and macOS
Weaknesses CWE-416

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash.
References

Subscriptions

Apple Ios And Ipados Macos Safari
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-06-29T21:29:27.255Z

Reserved: 2026-05-01T22:46:21.644Z

Link: CVE-2026-43712

cve-icon Vulnrichment

Updated: 2026-06-29T21:29:19.468Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-10T00:00:00Z

Links: CVE-2026-43712 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-30T02:15:03Z

Weaknesses