Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Published: 2026-06-29
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw was discovered in Safari’s memory handling. The issue is mitigated by improved memory management in newer releases. A malicious web page that triggers the use‑after‑free can cause Safari to terminate unexpectedly. The crash is confined to the browser process and does not execute arbitrary code, but it renders Safari unusable for that session.

Affected Systems

Apple Safari, iOS, iPadOS, macOS Tahoe, tvOS, and watchOS are affected by releases prior to 26.5.2 (Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6). The vulnerability is resolved in those updated releases.

Risk and Exploitability

The vulnerability can be triggered via malicious web content, implying an attack vector that relies on a web page served over a network. The exploitation results in a Safari process crash on macOS, iOS, iPadOS, tvOS, and watchOS, thereby denying service to the user session. Because the crash does not lead to code execution or data exfiltration, risks to confidentiality or integrity are limited; the primary impact is loss of availability for browsing activities. The CVSS score of 6.5 indicates moderate risk. The EPSS score is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog.

Generated by OpenCVE AI on August 4, 2026 at 08:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Apple software update that includes Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, and watchOS 26.6.
  • Enable built‑in safe browsing or web protection features such as macOS Gatekeeper or iOS Safe Browsing to sandbox content and reduce the risk of triggering the crash.
  • Install reputable web‑filtering or ad‑blocking extensions to block malicious content and mitigate the crash risk while the patch is pending.

Generated by OpenCVE AI on August 4, 2026 at 08:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Safari and Apple Platform Crash Vulnerability

Fri, 31 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Safari and Apple Platform Crash Vulnerability

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash. A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Tue, 30 Jun 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari

Tue, 30 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Crash in Safari

Mon, 29 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Crash in Safari
Weaknesses CWE-416
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Safari
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-27T20:14:21.504Z

Reserved: 2026-05-01T22:46:21.644Z

Link: CVE-2026-43717

cve-icon Vulnrichment

Updated: 2026-06-29T21:34:41.309Z

cve-icon NVD

Status : Modified

Published: 2026-06-29T20:17:36.363

Modified: 2026-07-27T21:16:55.867

Link: CVE-2026-43717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T08:30:05Z

Weaknesses