CVE-2026-43676
published 2026-06-29CVE-2026-43676: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.26%
17.1th percentile
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 26.5.2 | 26.5.2 |
| apple | ipados | < 26.5.2 | 26.5.2 |
| apple | iphone_os | < 26.5.2 | 26.5.2 |
| apple | macos | < 26.5.2 | 26.5.2 |
| apple | safari | < 26.5.2 | 26.5.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web out-of-bounds
vuldb·2026-06-30·CVSS 6.5
CVE-2026-43676 [MEDIUM] Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web out-of-bounds
A vulnerability was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. It has been rated as problematic. This affects an unknown part of the component Web Handler. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2026-43676. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
GHSA
An out-of-bounds access issue was addressed with improved bounds checking.
ghsa_unreviewed·2026-06-29
CVE-2026-43676 [MEDIUM] CWE-125 An out-of-bounds access issue was addressed with improved bounds checking.
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
No detection rules found.
No public exploits indexed.
2026-06-29
Published