CVE-2026-28984

Overview

Advisory: Apple Security Advisory

Impact:

Description: Processing maliciously crafted web content may lead to an unexpected Safari crash

Researchers: Artem Dinaburg of Trail of Bits via Anthropic CVD

Attribute Value
CVE CVE-2026-28984
Bugzilla 311883
Component JSC
Bug Class LogicError
Severity medium
Commit eba64ef44de39509…
Advisory Apple Advisory

Root Cause Analysis

The issue was addressed with improved memory handling.

Files Changed

Source Files

  • Source/JavaScriptCore/ftl/FTLOperations.cpp

Test Files

  • JSTests/stress/ftl-osr-exit-phantom-new-array-with-butterfly-having-a-bad-time.js