CVE-2026-28953
Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An out-of-bounds read in WebKit, triggered by malicious web content, could cause a denial-of-service via unexpected process crash on multiple Apple platforms.
Vulnerability
CVE-2026-28953 is an out-of-bounds read vulnerability in Apple's WebKit engine, which was addressed with improved bounds checking [1][2]. The issue is triggered when processing maliciously crafted web content, leading to an unexpected process crash [1]. The root cause is an insufficient bounds check that allows reading memory beyond allocated buffers.
Impact
A remote attacker could leverage this vulnerability by crafting a malicious webpage that, when visited by a user on an unpatched device, would cause the application processing the content (most commonly Safari or any app that uses WebView) to crash. This denial-of-service condition could transiently disrupt a user's work or browsing session. An app may be able to cause a denial-of-service, as noted in the official advisory [1].
Mitigation
Apple has released patches in multiple operating systems as of May 11, 2026 [1][2][3][4]. The following versions contain the fix: Safari 26.5, iOS 18.7.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5 [1][2][3]. Users are strongly advised to update their devices to the latest available software version to mitigate this vulnerability.
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- support.apple.com/en-us/127110nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127111nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127115nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127118nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127119nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127120nvdRelease NotesVendor Advisory
- support.apple.com/en-us/127121nvd
News mentions
1- Apple Patches Everything, (Mon, May 11th)SANS Internet Storm Center · May 11, 2026