Description
A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.
Published: 2026-08-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a memory corruption flaw triggered when the operating system processes maliciously crafted web content. It results from improper memory handling during rendering, which can corrupt internal data structures and potentially lead to memory corruption. While the description does not detail the exact consequences, such memory corruption raises concerns about system stability and security.

Affected Systems

Apple Safari, Apple iOS, Apple iPadOS, and Apple macOS are affected. The flaw was fixed in Safari 26.6.1, iOS 18.7.10 and 26.6.1, iPadOS 18.7.10 and 26.6.1, and macOS Tahoe 26.6.2. Users running earlier releases of any of these products are at risk of memory corruption when rendering web content.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity level, while the EPSS score of less than 1% suggests that exploitation is currently unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the most probable attack vector involves delivering maliciously crafted web pages or content that is rendered by Safari or the web content framework of the operating system. The memory corruption could lead to undefined behavior, potentially affecting confidentiality, integrity, and availability of the affected systems.

Generated by OpenCVE AI on August 27, 2026 at 02:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Apple updates: install Safari 26.6.1, iOS 18.7.10 or 26.6.1, iPadOS 18.7.10 or 26.6.1, and macOS Tahoe 26.6.2.
  • Until the update is applied, avoid visiting untrusted web pages or downloading unverified content that could trigger the rendering path.
  • Continuously monitor system logs and process activity for indicators of compromise or abnormal behavior that might signal exploitation of this memory corruption flaw.

Generated by OpenCVE AI on August 27, 2026 at 02:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title webkitgtk: Processing maliciously crafted web content may lead to memory corruption
Weaknesses CWE-120
References
Metrics threat_severity

None

threat_severity

Important


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Apple OS Memory Corruption Vulnerability

Tue, 18 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
Apple safari
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os
Apple safari

Tue, 18 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Apple OS Memory Corruption Vulnerability

Tue, 18 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption. A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.
References

Tue, 18 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption via Malicious Web Content in Apple iOS and macOS
Weaknesses CWE-120
CWE-787

Tue, 18 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 17 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption via Malicious Web Content in Apple iOS and macOS
Weaknesses CWE-120
CWE-787

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Safari
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-19T03:55:53.857Z

Reserved: 2026-05-01T22:46:27.820Z

Link: CVE-2026-43794

cve-icon Vulnrichment

Updated: 2026-08-18T12:56:29.250Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-17T22:17:11.457

Modified: 2026-08-19T04:17:20.470

Link: CVE-2026-43794

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-17T21:31:33Z

Links: CVE-2026-43794 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T02:30:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')