VYPR
Medium severity6.5NVD Advisory· Published Jun 29, 2026· Updated Jul 27, 2026

CVE-2026-43718

CVE-2026-43718

Description

A stack overflow was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected products

7
  • Apple Inc./Safarillm-fuzzy2 versions
    = 26.5.2+ 1 more
    • (no CPE)range: = 26.5.2
    • cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*range: <26.5.2
  • Apple Inc./iOSllm-fuzzy
    Range: = 26.5.2
  • cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
    Range: <26.5.2
  • cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
    Range: <26.5.2
  • Apple Inc./macOS2 versions
    cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*range: >=26.0,<26.5.2
    • (no CPE)range: = 26.5.2

Patches

Vulnerability mechanics

References

6

News mentions

1