{"id":13885,"date":"2026-05-13T18:51:00","date_gmt":"2026-05-14T01:51:00","guid":{"rendered":"https:\/\/www.runwayritz.com\/index.php\/2026\/05\/13\/safari-26-5-fixes-webkit-bugs-that-could-crash-safari-or-expose-user-data\/"},"modified":"2026-05-13T19:34:58","modified_gmt":"2026-05-14T02:34:58","slug":"safari-26-5-fixes-webkit-bugs-that-could-crash-safari-or-expose-user-data","status":"publish","type":"post","link":"https:\/\/www.runwayritz.com\/index.php\/2026\/05\/13\/safari-26-5-fixes-webkit-bugs-that-could-crash-safari-or-expose-user-data\/","title":{"rendered":"Safari 26.5 fixes WebKit bugs that could crash Safari or expose user data"},"content":{"rendered":"<p><br \/>\n<\/p>\n<p>Apple has published a full list of security fixes for Safari 26.5, including a WebKit vulnerability that could allow maliciously crafted web content to expose sensitive user information. Here are the details.<\/p>\n<p>On that day, the company released the full security content of each update, and you can find more details about it here.<\/p>\n<p>Now, Apple has released security content for Safari 26.5, which includes fixes for 20 WebKit vulnerabilities, as well as a WebRTC issue that can cause unexpected process crashes.<\/p>\n<div id=\"\">\n<h2 class=\"wp-block-heading\" id=\"h-webkit\">WebKit<\/h2>\n<p>Available for: macOS Sonoma and macOS Sequoia<\/p>\n<p>Impact: Malformed web content processing may prevent the Content Security Policy from being applied<\/p>\n<p>Description: The authentication problem has been addressed with an improved logic.<\/p>\n<p>WebKit Bugzilla: 308906<\/p>\n<p>CVE-2026-43660: Cantina<\/p>\n<h3 class=\"wp-block-heading\">WebKit<\/h3>\n<p>Available for: macOS Sonoma and macOS Sequoia<\/p>\n<p>Impact: Malformed web content processing may prevent the Content Security Policy from being applied<\/p>\n<p>Description: An issue was addressed with improved input validation.<\/p>\n<p>WebKit Bugzilla: 308675<\/p>\n<p>CVE-2026-28907: Cantina<\/p>\n<h3 class=\"wp-block-heading\">WebKit<\/h3>\n<p>Available for: macOS Sonoma and macOS Sequoia<\/p>\n<p>Impact: Processing poorly crafted web content may expose sensitive user information<\/p>\n<p>Description: This issue was addressed with improved access restrictions.<\/p>\n<p>WebKit Bugzilla: 309698<\/p>\n<p>CVE-2026-28962: Luke Francis, Vaagn Vardanian, kwak kiyong \/ kakaogames, Vitaly Simonovich, Adel Bouachraoui, greenbynox<\/p>\n<h3 class=\"wp-block-heading\">WebKit<\/h3>\n<p>Available for: macOS Sonoma and macOS Sequoia<\/p>\n<p>Impact: Processing poorly designed web content may lead to unexpected Safari crashes<\/p>\n<p>Description: The problem was addressed with improved memory management.<\/p>\n<p>WebKit Bugzilla: 307669<\/p>\n<p>CVE-2026-43658: Do Young Park<\/p>\n<h3 class=\"wp-block-heading\">WebKit<\/h3>\n<p>Available for: macOS Sonoma and macOS Sequoia<\/p>\n<p>Impact: Processing poorly designed web content may lead to unexpected process crashes<\/p>\n<p>Description: The problem was addressed with improved memory management.<\/p>\n<p>WebKit Bugzilla: 308545<\/p>\n<p>CVE-2026-28905: Yuhao Hu, Yuanming Lai, Chenggang Wu, and Zhe Wang<\/p>\n<p>WebKit Bugzilla: 308707<\/p>\n<p>CVE-2026-28847: DARKNAVY (@DarkNavyOrg), Anonymous working with TrendaI Zero Day Initiative, Daniel Rhea<\/p>\n<p>WebKit Bugzilla: 309601<\/p>\n<p>CVE-2026-28904: Luka Ra\u010dki<\/p>\n<p>WebKit Bugzilla: 310880<\/p>\n<p>CVE-2026-28955: wac and Kookhwan Lee work with TrendAI Zero Day Initiative<\/p>\n<p>WebKit Bugzilla: 310303<\/p>\n<p>CVE-2026-28903: Mateusz Krzywicki (Verify.io)<\/p>\n<p>WebKit Bugzilla: 309628<\/p>\n<p>CVE-2026-28953: Maher Azzouzi<\/p>\n<p>WebKit Bugzilla: 309861<\/p>\n<p>CVE-2026-28902: Tristan Madani (@TristanInSec) from Talence Security, Nathaniel Oh (@calysteon)<\/p>\n<p>WebKit Bugzilla: 310207<\/p>\n<p>CVE-2026-28901: Aisle security research team (Joshua Rogers, Luigino Camastra, Igor Morgenstern, and Guido Vranken), Maher Azzouzi, Ngan Nguyen of Calif.io<\/p>\n<p>WebKit Bugzilla: 311631<\/p>\n<p>CVE-2026-28913: unknown researcher<\/p>\n<h3 class=\"wp-block-heading\">WebKit<\/h3>\n<p>Available for: macOS Sonoma and macOS Sequoia<\/p>\n<p>Impact: Processing poorly designed web content may lead to unexpected process crashes<\/p>\n<p>Description: An issue with running after free was addressed with improved memory management.<\/p>\n<p>WebKit Bugzilla: 313939<\/p>\n<p>CVE-2026-28883: kwak kiyong \/ kakaogames<\/p>\n<h3 class=\"wp-block-heading\">WebKit<\/h3>\n<p>Available for: macOS Sonoma and macOS Sequoia<\/p>\n<p>Impact: The application may have access to sensitive user data<\/p>\n<p>Description: This issue was addressed with improved data protection.<\/p>\n<p>WebKit Bugzilla: 311228<\/p>\n<p>CVE-2026-28958: Cantina<\/p>\n<h3 class=\"wp-block-heading\">WebKit<\/h3>\n<p>Available for: macOS Sonoma and macOS Sequoia<\/p>\n<p>Impact: Processing poorly designed web content may lead to unexpected process crashes<\/p>\n<p>Description: An issue was addressed with improved input validation.<\/p>\n<p>WebKit Bugzilla: 310527<\/p>\n<p>CVE-2026-28917: Vitaly Simonovich<\/p>\n<h3 class=\"wp-block-heading\">WebKit<\/h3>\n<p>Available for: macOS Sonoma and macOS Sequoia<\/p>\n<p>Impact: Processing poorly designed web content may lead to unexpected Safari crashes<\/p>\n<p>Description: An issue with running after free was addressed with improved memory management.<\/p>\n<p>WebKit Bugzilla: 310234<\/p>\n<p>CVE-2026-28947: dr3dd<\/p>\n<p>WebKit Bugzilla: 310544<\/p>\n<p>CVE-2026-28946: Gia Bui (@yabeow) from Calif.io, dr3dd, w0wbox<\/p>\n<p>WebKit Bugzilla: 312180<\/p>\n<p>CVE-2026-28942: Milad Nasr and Nicholas Carlini and Claude, Anthropic<\/p>\n<h3 class=\"wp-block-heading\">WebKit<\/h3>\n<p>Available for: macOS Sonoma and macOS Sequoia<\/p>\n<p>Impact: A malicious iframe may use the download settings of another website<\/p>\n<p>Description: The issue was addressed with improved UI management.<\/p>\n<p>CVE-2026-28971: Khiem Tran<\/p>\n<p>WebKit Bugzilla: 311288<\/p>\n<h3 class=\"wp-block-heading\">WebRTC<\/h3>\n<p>Available for: macOS Sonoma and macOS Sequoia<\/p>\n<p>Impact: Processing poorly designed web content may lead to unexpected process crashes<\/p>\n<p>Description: The problem was addressed with improved memory management.<\/p>\n<p>WebKit Bugzilla: 311131<\/p>\n<p>CVE-2026-28944: Kenneth Hsu of Palo Alto Networks, J\u00e9r\u00f4me DJOUDER, dr3dd<\/p>\n<\/div>\n<p>If your Mac is compatible with Safari 26.5, it would be a good idea to make sure you&#8217;re running the latest version as soon as possible.<\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>Apple has published a full list of security fixes for Safari 26.5, including a WebKit vulnerability that could allow maliciously crafted web content to expose sensitive user information. Here are the details. On that day, the company released the full security content of each update, and you can find more details about it here. Now, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":13886,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[],"class_list":{"0":"post-13885","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-smartphones-tablets"},"_links":{"self":[{"href":"https:\/\/www.runwayritz.com\/index.php\/wp-json\/wp\/v2\/posts\/13885","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.runwayritz.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.runwayritz.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.runwayritz.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.runwayritz.com\/index.php\/wp-json\/wp\/v2\/comments?post=13885"}],"version-history":[{"count":1,"href":"https:\/\/www.runwayritz.com\/index.php\/wp-json\/wp\/v2\/posts\/13885\/revisions"}],"predecessor-version":[{"id":13887,"href":"https:\/\/www.runwayritz.com\/index.php\/wp-json\/wp\/v2\/posts\/13885\/revisions\/13887"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.runwayritz.com\/index.php\/wp-json\/wp\/v2\/media\/13886"}],"wp:attachment":[{"href":"https:\/\/www.runwayritz.com\/index.php\/wp-json\/wp\/v2\/media?parent=13885"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.runwayritz.com\/index.php\/wp-json\/wp\/v2\/categories?post=13885"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.runwayritz.com\/index.php\/wp-json\/wp\/v2\/tags?post=13885"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}