Vulnerabilities · 75 days ago

Apple Closes Browser-to-Kernel Paths Across Its Fleet

Most of this release is browser-surface cleanup. The real risk sits in the small set of kernel memory bugs and sandbox escapes, because those are the cases where a malicious website can move from a browser crash to device-level compromise.

Apple shipped 37 fixes across iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2. Most of the issues are in WebKit, but the high-value ones include CVE-2026-43724 and CVE-2026-39868 in the kernel, plus WebKit flaws that can push restricted web content outside the sandbox. Apple also said at least four defects were identified using AI, which points to a sourcing trend, not a new attacker capability.

CVE-2026-39868

NVD KEV

CVSS 9.1 CRITICAL: this issue was addressed with improved input validation. EPSS 1% (66th percentile).

CVE-2026-43724

NVD KEV

CVSS 7.8 HIGH: the issue was addressed with improved input sanitization. EPSS 0.3% (25th percentile).

Timeline

Sources

5 sources covering this story

Entities

Part of the PlainSec briefing for 2026-07-02

Editions

Related stories