CVE-2026-39872
published 2026-06-29CVE-2026-39872: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing…
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.22%
12.7th percentile
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 26.5.2 | 26.5.2 |
| apple | ipados | < 26.5.2 | 26.5.2 |
| apple | iphone_os | < 26.5.2 | 26.5.2 |
| apple | macos | < 26.5.2 | 26.5.2 |
| apple | safari | < 26.5.2 | 26.5.2 |
| webkitgtk | webkitgtk | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web denial of service
vuldb·2026-06-30·CVSS 6.5
CVE-2026-39872 [MEDIUM] Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web denial of service
A vulnerability was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Handler. Performing a manipulation results in denial of service.
This vulnerability is known as CVE-2026-39872. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
GHSA
The issue was addressed with improved memory handling.
ghsa_unreviewed·2026-06-29
CVE-2026-39872 [MEDIUM] CWE-119 The issue was addressed with improved memory handling.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash.
Red Hat
webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash
vendor_redhat·2026-07-10·CVSS 6.5
CVE-2026-39872 [MEDIUM] CWE-416 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash
webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash.
A flaw was found in WebKitGTK. Processing maliciously crafted web content can trigger a use-after-free due to improper memory handling, resulting in an unexpected process crash.
Package: pywebkitgtk (Red Hat Enterprise Linux 6) - Out of support scope
Package: webkitgtk (Red Hat Enterprise Linux 6) - Out of support scope
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Out of support scope
Package: webkitgtk4 (Red Hat Enterprise Linux 7) - Out of support scope
Package: we
No detection rules found.
No public exploits indexed.
2026-06-29
Published