Description
A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.
Published: 2026-08-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption
Action: Patch
AI Analysis

Impact

A memory corruption flaw in WebKit within Apple’s Safari and related operating systems can be triggered by maliciously crafted web content. The failure arises from insufficient memory handling, resulting in memory corruption that may cause undefined behavior, including potential denial of service or compromise of confidentiality and integrity. The CVSS score of 8.8 classifies it as high severity. The available data indicates that malicious content processed by Safari or other WebKit components can lead to memory corruption, and no other weaknesses are cited.

Affected Systems

Apple’s Safari is affected in version 26.6.1; iOS is affected in releases 18.7.10 and 26.6.1; iPadOS is affected in releases 18.7.10 and 26.6.1; macOS Tahoe is affected in 26.6.2; tvOS is affected in 27; visionOS is affected in 27; and watchOS is affected in 27.

Risk and Exploitability

The high CVSS score underscores the severity, yet the EPSS score of less than 1% indicates a very low likelihood of exploitation currently. The vulnerability is not listed in CISA’s KEV catalog. The most probable attack vector involves delivery of maliciously crafted web pages or content that is rendered by Safari or the platform’s WebKit framework. Because the issue is a memory corruption fault, an attacker achieving exploitation could potentially cause a crash or, under the right conditions, gain control of execution or compromise system data.

Generated by OpenCVE AI on September 21, 2026 at 07:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Apple software updates that include Safari 26.6.1, iOS 18.7.10 / 26.6.1, iPadOS 18.7.10 / 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27.
  • Restrict user interaction with untrusted or suspicious web content that could cause Safari or WebKit to process malicious payloads, especially in environments where users frequently visit third‑party sites.
  • Enable or enforce built‑in web‑content protection mechanisms (such as content blockers or safe browsing features) to reduce exposure to potentially malicious pages before they are rendered by Safari or web‑based apps.

Generated by OpenCVE AI on September 21, 2026 at 07:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption. A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.
References

Thu, 27 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title webkitgtk: Processing maliciously crafted web content may lead to memory corruption
Weaknesses CWE-120
References
Metrics threat_severity

None

threat_severity

Important


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Apple OS Memory Corruption Vulnerability

Tue, 18 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
Apple safari
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os
Apple safari

Tue, 18 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Apple OS Memory Corruption Vulnerability

Tue, 18 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption. A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.
References

Tue, 18 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption via Malicious Web Content in Apple iOS and macOS
Weaknesses CWE-120
CWE-787

Tue, 18 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 17 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption via Malicious Web Content in Apple iOS and macOS
Weaknesses CWE-120
CWE-787

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Safari
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:51:46.476Z

Reserved: 2026-05-01T22:46:27.820Z

Link: CVE-2026-43794

cve-icon Vulnrichment

Updated: 2026-08-18T12:56:29.250Z

cve-icon NVD

Status : Modified

Published: 2026-08-17T22:17:11.457

Modified: 2026-09-14T21:17:11.910

Link: CVE-2026-43794

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-17T21:31:33Z

Links: CVE-2026-43794 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T07:15:07Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')