CVE-2026-43720: Safari Use-After-Free DoS Vulnerability
A use-after-free memory vulnerability in Apple Safari and related systems allows attackers to crash Safari by tricking users into viewing specially crafted web content. The flaw stems from improper memory management that leaves dangling references to freed memory, which attackers can exploit to trigger an unexpected application crash. While the vulnerability requires user interaction (visiting a malicious website), it affects a widely used browser across multiple Apple platforms.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.5 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Weaknesses (CWE)
- CWE-416
- Affected products
- 4 configuration(s)
- Published / Modified
- 2026-06-29 / 2026-07-27
NVD description (verbatim)
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
6 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-43720 is a use-after-free vulnerability (CWE-416) in WebKit's memory management subsystem. When Safari processes maliciously crafted web content, the application may reference memory that has already been freed, leading to undefined behavior and typically a crash. The vulnerability is triggered during normal web browsing without requiring elevated privileges. Apple addressed this through improved memory lifecycle management and bounds checking in affected components.
Business impact
Organizations with a significant Apple user base face operational disruption when employees encounter malicious web content. While the vulnerability results in denial of service rather than data theft or system compromise, repeated crashes degrade productivity and user experience. In environments where Safari is a primary browser or where users frequently access untrusted websites, the risk is amplified. The public nature of the fix (visible patch versions) means attackers can reverse-engineer exploitation techniques post-disclosure.
Affected systems
Safari 26.5.2 and earlier on macOS; iOS and iPadOS versions prior to 26.5.2; tvOS and visionOS versions prior to 26.6; watchOS prior to 26.6. Any device running these vulnerable operating systems with Safari or embedded WebKit components is affected. This includes iPhones, iPads, Mac computers, Apple TVs, Vision Pro devices, and Apple Watches.
Exploitability
The vulnerability requires user interaction—specifically, the user must visit or be directed to a malicious website. It cannot be exploited remotely without social engineering or drive-by download tactics. The low attack complexity and network accessibility make it suitable for mass-targeting campaigns if combined with web-based delivery mechanisms (e.g., malvertising, phishing). No known public exploit code exists at present, and the vulnerability is not tracked on CISA's Known Exploited Vulnerabilities list.
Remediation
Update all affected Apple devices to patched versions: Safari 26.5.2 or later, iOS 26.5.2 or later, iPadOS 26.5.2 or later, macOS Tahoe 26.5.2 or later, tvOS 26.6 or later, visionOS 26.6 or later, and watchOS 26.6 or later. Enable automatic updates where possible to ensure timely patching. Organizations should prioritize updates for devices used by employees who regularly access external web content.
Patch guidance
Apply updates through each platform's standard update mechanism: iOS/iPadOS via Settings > General > Software Update; macOS via System Settings > General > Software Update; watchOS via the Watch app on a paired iPhone; tvOS via Settings > System > Software Updates; visionOS via Settings > General > About. For macOS specifically, verify you are updating to macOS Tahoe 26.5.2 or later, as version numbering changed in this release. Consider staggered rollout in enterprise environments to identify any compatibility issues before full deployment.
Detection guidance
Monitor system logs and crash reports for Safari process terminations with memory-related signatures, particularly those occurring during web browsing sessions. EDR solutions may flag heap corruption or use-after-free patterns in memory dumps. Network-level detection is difficult; however, organizations using web filtering can identify malicious hosting infrastructure once documented in threat intelligence feeds. Collect crash logs from affected devices to correlate timing and content URLs with confirmed malicious sources.
Why prioritize this
Although this is a medium-severity vulnerability limited to denial of service, Apple's broad ecosystem means affected devices are numerous in typical enterprise environments. The requirement for user interaction—not a barrier in practice given phishing and malvertising—combined with the lack of authentication or special privileges makes it an attractive target for mass-campaign disruption. Prioritize patching user-facing devices (personal computers, phones) over infrastructure. Given the public availability of patch information, active exploitation becomes more likely in the weeks following disclosure.
Risk score, explained
The CVSS 3.1 score of 6.5 (Medium) reflects low complexity exploitation over the network with user interaction required, resulting in high availability impact but no confidentiality or integrity loss. While the score appropriately captures the denial-of-service nature, context matters: in organizations where Safari is a primary browser or where employees access untrusted content, the practical risk may be higher due to attack frequency. The lack of KEV designation indicates no coordinated active exploitation has been confirmed, reducing urgency relative to critical vulnerabilities, but post-patch analysis may change this status.
Frequently asked questions
Can this vulnerability steal my passwords or personal data?
No. This use-after-free vulnerability causes Safari to crash; it does not allow attackers to read memory, steal passwords, or access browser data. The impact is limited to denial of service (application crash) and potential loss of unsaved work.
Do I need to update if I don't use Safari?
If you use Google Chrome, Firefox, or another non-WebKit browser on your device, you are not directly affected by this Safari vulnerability. However, iOS and iPadOS users should note that many third-party browsers use Apple's WebKit engine, so check your preferred browser's underlying technology. macOS and tvOS users who have disabled Safari entirely face minimal risk.
How likely is it that I'll encounter this vulnerability in the wild?
The vulnerability is not currently tracked as being exploited in active campaigns, and there is no public exploit code. However, attackers could easily develop one now that patches are public. The risk is highest if you browse untrusted websites, click suspicious links, or are targeted by phishing emails with malicious URLs. Most users in corporate environments with web filtering face lower exposure.
What should I do if Safari keeps crashing?
Update to the patched version immediately. If you cannot update immediately, avoid visiting unfamiliar websites or clicking links in emails from untrusted senders. If crashes persist after patching, report them to Apple with crash logs, as you may have encountered a different issue. Contact your IT support team for assistance in enterprise settings.
This analysis is based on official Apple security advisories and CVE data as of July 27, 2026. Patch version numbers and affected product versions should be verified directly against Apple's official security updates before deployment. This vulnerability has not been confirmed as actively exploited in the wild; however, exploitation is feasible and may increase over time. Organizations should conduct internal testing before enterprise-wide patch rollout. SEC.co does not provide legal or compliance advice; consult your internal security and legal teams regarding incident response obligations specific to your jurisdiction. Source: NVD (public-domain), retrieved 2026-08-08. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-11073MEDIUMChrome WebGL Use-After-Free Information Disclosure
- CVE-2026-11208MEDIUMUse-After-Free in Chrome Codecs – Information Disclosure Vulnerability
- CVE-2026-11249MEDIUMChrome Use-After-Free Information Disclosure Vulnerability
- CVE-2026-11628MEDIUMChrome Use-After-Free in Ozone (Local Heap Corruption)
- CVE-2026-12015MEDIUMUse-After-Free in Chrome Autofill Information Disclosure
- CVE-2026-13879MEDIUMChrome Bluetooth Use-After-Free Memory Disclosure Vulnerability
- CVE-2026-14048MEDIUMChrome Chromecast Use-After-Free Memory Disclosure
- CVE-2026-39872MEDIUMSafari Memory Handling Vulnerability – CVSS 6.5