Description
A stack overflow was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Published: 2026-06-29
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack overflow arises when Safari processes specially crafted web content. The flaw was addressed through improved input validation in version 26.5.2 and later across Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS. If malicious content is delivered, the browser may crash, resulting in a denial‑of‑service condition. The bug is a stack‑smashing issue (CWE‑121) and does not allow code execution or data exfiltration.

Affected Systems

Apple’s Safari web browser, iOS, iPadOS, macOS Tahoe, tvOS, visionOS and watchOS are affected. The vulnerability is addressed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6 and watchOS 26.6. Devices running older releases without the patch remain vulnerable.

Risk and Exploitability

A stack overflow arises when Safari processes specially crafted web content, potentially causing the browser to crash unexpectedly. With a CVSS score of 6.5 the flaw is of moderate severity. EPSS score of 0.00437 indicates a very low exploitation probability, and the flaw is not listed in CISA KEV, indicating no confirmed exploitation. The vulnerability requires delivery of malicious web content, so it can be triggered by an attacker who hosts or lures the victim to a crafted page. The crash limits the potential damage to a denial‑of‑service event on a single device. Nonetheless, patching is recommended to prevent abuse via the crash.

Generated by OpenCVE AI on August 4, 2026 at 08:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Safari, iOS, iPadOS, and macOS to version 26.5.2 or later, which includes the stack overflow fix.
  • Enable automatic updates to receive future patches without manual intervention.
  • If an immediate update is unavailable, block or filter web content that could contain malicious packages, for example by using a trusted security gateway or web‑content filter.

Generated by OpenCVE AI on August 4, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Safari Stack Overflow Crash via Malicious Web Content

Sun, 02 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Safari, iOS, iPadOS and macOS Stack Overflow Causing Crash

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A stack overflow was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash. A stack overflow was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Tue, 30 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Title Safari, iOS, iPadOS and macOS Stack Overflow Causing Crash
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari

Tue, 30 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Title Stack Overflow in Safari Causes Crash via Malicious Web Content
Weaknesses CWE-120

Mon, 29 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Title Stack Overflow in Safari Causes Crash via Malicious Web Content
Weaknesses CWE-120

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description A stack overflow was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Safari
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-27T20:12:24.921Z

Reserved: 2026-05-01T22:46:21.645Z

Link: CVE-2026-43718

cve-icon Vulnrichment

Updated: 2026-06-29T21:18:33.232Z

cve-icon NVD

Status : Modified

Published: 2026-06-29T20:17:36.457

Modified: 2026-07-27T21:16:56.023

Link: CVE-2026-43718

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T08:30:05Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow