Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to memory corruption.
Published: 2026-06-29
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free issue was identified in Apple software that could be triggered by processing maliciously crafted web content, leading to memory corruption. The vulnerability stems from improper memory management after object deallocation and is classified as a use‑after‑free flaw, correlating with CWE‑416. Depending on the context, memory corruption could potentially enable an attacker to execute arbitrary code or compromise system integrity.

Affected Systems

Apple products – Safari, iOS, iPadOS, and macOS – are affected by versions released before 26.5.2. The vulnerability is fixed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.

Risk and Exploitability

Because EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, a precise exploitation probability cannot be quantified. The impact is limited to memory corruption; however, if an attacker can inject or drive crafted content through the browser or embedded web views, local privilege or remote code execution could be possible. The likely attack vector involves visiting malicious web pages or loading infected web resources through Safari or system web components. The absence of a CVSS score means that organizations should treat the issue with caution and assess the risk based on the potential for arbitrary code execution in their environment.

Generated by OpenCVE AI on June 29, 2026 at 21:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Safari 26.5.2 or later on all affected devices
  • Update iOS, iPadOS, and macOS to 26.5.2 or later
  • If an immediate update is not feasible, restrict browser access to untrusted networks or sites through content filtering or network segmentation

Generated by OpenCVE AI on June 29, 2026 at 21:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 29 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Title Use-After‑Free Exploit via Malicious Web Content Causing Memory Corruption
Weaknesses CWE-416

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to memory corruption.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-06-29T21:32:22.003Z

Reserved: 2026-05-01T22:46:21.646Z

Link: CVE-2026-43731

cve-icon Vulnrichment

Updated: 2026-06-29T21:32:14.637Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-29T21:45:04Z

Weaknesses