CVE-2026-28953: The issue was addressed with improved memory handling.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
Security readout for executives and security teams
Plain-English summary
Apple fixed a high-severity memory handling issue in web content processing. A user who opens malicious web content could experience an unexpected process crash. The source bundle does not prove active exploitation or remote code execution, but the affected Apple ecosystem breadth makes patching important.
Executive priority
Treat as a high-priority patching item for Apple fleets and browsers, especially where users browse external sites. There is no provided evidence of active exploitation, so this is urgent hygiene rather than confirmed incident response.
Technical view
CVE-2026-28953 is described as a memory handling flaw associated with CWE-119 and CWE-120. The CVSS 3.1 score is 8.8 with network attack vector, low complexity, no privileges, and required user interaction. Apple lists fixes across Safari and multiple operating systems.
Likely exposure
Organizations may be exposed where Safari or Apple platforms remain below Safari 26.5, iOS/iPadOS 18.7.9 or 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, or watchOS 26.5. Red Hat references exist, but product impact should be confirmed from Red Hat advisories.
Exploitation context
The provided evidence says maliciously crafted web content may trigger a process crash. KEV status is false, and the bundle includes no cited evidence of active exploitation. User interaction is required according to the CVSS vector.
Researcher notes
The public description is sparse: memory handling, crafted web content, and unexpected crash are the confirmed technical details. The affected version data in the bundle uses placeholder values, so rely on Apple and Red Hat advisories for exact product applicability.
Mitigation direction
Apply the Apple fixed versions listed in the advisory bundle.
Prioritize browsers and user endpoints that process untrusted web content.
Review Red Hat advisories for any applicable packaged dependency exposure.
Use vendor guidance for any product-specific mitigations not named here.
Validation and detection
Inventory Safari and Apple OS versions against the fixed release list.
Confirm patch deployment on managed macOS, iOS, iPadOS, watchOS, tvOS, and visionOS assets.
Check vulnerability scanners for CVE-2026-28953 coverage and stale detections.
Review Red Hat VEX and errata applicability before treating Linux systems as affected.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-119: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.