CVE-2026-28857
Overview
Advisory: Apple Security Advisory
Impact:
Description: Processing maliciously crafted web content may lead to an unexpected process crash
Researchers: Minse Kim, Narcis Oliveras Fontàs, Söhnke Benedikt Fischedick (Tripton), Daniel Rhea, Nathaniel Oh (@calysteon)
| Attribute | Value |
|---|---|
| CVE | CVE-2026-28857 |
| Bugzilla | 307723 |
| Component | JSC |
| Bug Class | LogicError |
| Severity | medium |
| Commit | 4c82252b8b2face3… |
| Advisory | Apple Advisory |
Root Cause Analysis
The issue was addressed with improved memory handling.
Files Changed
Source Files
Source/JavaScriptCore/runtime/JSGenericTypedArrayViewPrototypeFunctions.h
Test Files
JSTests/stress/growable-sharedarraybuffer-parallel-grow-during-prototype-methods.js