CVE-2026-28947 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: May 12, 2026
Apple Safari - Denial of Service
Published: May 11, 2026Updated: May 12, 2026Remote Exploitable
Overview
Apple iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5 contain a use-after-free vulnerability caused by improper memory management in Safari, letting attackers cause a crash via malicious web content, exploit requires crafted web content.
Severity & Score
Severity: High
CVSS Score: 8.8
Impact
Attackers can cause Safari to crash, leading to denial of service.
Mitigation
Update to version 26.5 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-28947
- Severity
- High
- CVSS Score
- 8.8
- Type
- use_after_free
- Status
- unconfirmed
CWE
- CWE-416
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H