CVE-2026-28944
Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An out-of-bounds read in WebKit, addressed with improved bounds checking, could cause a denial-ofservice when processing malicious web content.
Vulnerability
Overview
CVE-2026-28944 is an out-of-bounds read vulnerability in WebKit, the browser engine used by Safari and other Apple applications. The issue was addressed with improved bounds checking, as described in Apple's security advisories for iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, and Safari 26.5 [1][2][3][4]. The root cause is an out-of-bounds read, which can lead to unexpected behavior when processing specially crafted web content.
Exploitation
An attacker can exploit this vulnerability by luring a victim to visit a maliciously crafted webpage. No additional privileges or user interaction beyond browsing are required, as the attack vector is through web content. The vulnerability is present in WebKit, which is used by Safari and other applications that render web content on affected Apple platforms [1][2][3][4].
Impact
Successful exploitation could cause an unexpected process crash, leading to a denial-of-service condition. The impact is limited to application termination, and there is no indication of arbitrary code execution or data exfiltration from the available information [1][2][3][4].
Mitigation
Apple has released patches for this vulnerability in iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, and Safari 26.5. Users are advised to update their devices to the latest available versions to mitigate the risk [1][2][3][4].
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: = 26.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- support.apple.com/en-us/127110nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127115nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127120nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127121nvd
News mentions
1- Apple Patches Everything, (Mon, May 11th)SANS Internet Storm Center · May 11, 2026