CVE-2026-28946

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References
Configurations

Configuration 1 (hide)

cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

13 May 2026, 21:16

Type Values Removed Values Added
References
  • () https://support.apple.com/en-us/127121 -
Summary (en) A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Tahoe 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash. (en) A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.

13 May 2026, 14:08

Type Values Removed Values Added
References () https://support.apple.com/en-us/127115 - () https://support.apple.com/en-us/127115 - Release Notes, Vendor Advisory
First Time Apple macos
Apple
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

12 May 2026, 18:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-416

11 May 2026, 21:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-11 21:18

Updated : 2026-05-13 21:16


NVD link : CVE-2026-28946

Mitre link : CVE-2026-28946

CVE.ORG link : CVE-2026-28946


JSON object : View

Products Affected

apple

  • macos
CWE
CWE-416

Use After Free