CVE-2026-28946
Memory Corruption in macOS Tahoe via Safari Content
Publication date: 2026-05-11
Last updated on: 2026-05-11
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | safari | to 26.5 (inc) |
| apple | macos_tahoe | 26.5 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a use-after-free issue related to memory management in Safari on macOS Tahoe. It occurs when processing maliciously crafted web content, which can cause Safari to crash unexpectedly.
How can this vulnerability impact me? :
The vulnerability can lead to an unexpected crash of the Safari browser when it processes malicious web content. This may disrupt your browsing experience and could potentially be exploited to cause denial of service.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, update your system to macOS Tahoe 26.5 or later, where the issue has been fixed.
Avoid processing maliciously crafted web content in Safari until the update is applied.