VDB

CVE-2026-43676

CVE-2026-43676 PUBLISHED CVSS 6.5 MEDIUM

Reported by apple · Published June 29, 2026

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
AppleSafari0
AppleiOS and iPadOS0
ApplemacOS0
AppleSafari0
AppleiOS and iPadOS0
ApplemacOS0

Timeline

  • Jun 29, 2026 CVE Published
  • Jun 29, 2026 CVE Updated
  • Jun 30, 2026 EPSS Score
  • Jun 30, 2026 Coalition ESS Score
  • Jul 21, 2026 Distribution Patch
  • Jul 21, 2026 Security Advisory
  • Jul 21, 2026 Distribution Patch
  • Jul 21, 2026 Security Advisory
  • Jul 21, 2026 Distribution Patch
  • Jul 21, 2026 Security Advisory

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›