Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
In plain language
AI Low urgencyCVE-2026-43716 is a Safari/iPhone/iPad/Mac Safari bug where malicious web content can crash the browser, so you should update Safari/iOS/macOS to the fixed versions if you use it regularly.
CVE-2026-43716 is a Safari web-content memory-handling flaw (CWE-119/CWE-416) that can be triggered when a user processes crafted web content, leading to an unexpected Safari crash.
What to do now
- Check which system you’re using (macOS, iOS, or iPadOS) and confirm your current version/build.
- Check the Safari version you’re running on that device (it updates with the OS on Apple devices).
- Update immediately to the fixed versions: Safari 26.5.2 (Safari), iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.
- After updating, test that Safari can open the sites you normally use and that your usual extensions (if any) still load.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-43716 and every CVE in our database. Create a free account — no credit card required.
Create Free Account