CVE-2026-43804

MEDIUM

Apple Safari - Denial of Service

Title source: rule
STIX 2.1

Description

This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. Visiting a website may lead to an app denial-of-service.

Scores

CVSS v3 6.5
EPSS 0.0030
EPSS Percentile 22.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (9)
Apple/iOS and iPadOS < 26.6
apple/ipados < 26.6
apple/iphone_os < 26.6
Apple/macOS < 26.6
apple/macos 26.0 - 26.6
Apple/Safari < 26.6
apple/safari < 26.6
Apple/visionOS < 26.6
apple/visionos < 26.6
Published Jul 27, 2026
Tracked Since Jul 28, 2026