Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use-after-free error in Safari and its companion Apple platforms can be triggered by maliciously crafted web content, resulting in an unexpected crash of the browser application.

Affected Systems

Apple Safari, iOS, iPadOS, Apple macOS, tvOS, visionOS, and watchOS. Versions before 26.6 of each product are affected; the issue is fixed in 26.6 and later releases of Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.

Risk and Exploitability

The vulnerability is not publicly associated with a known exploit and is not listed in CISA’s KEV catalog. The CVSS score of 5.5 indicates moderate severity. The EPSS score of <1% indicates a very low but nonzero exploitation probability. Attackers would need to deliver malicious web content to a user’s Safari session; no privileged state or remote code execution is indicated. The impact is limited to a denial‑of‑service by crashing the browser.

Generated by OpenCVE AI on August 12, 2026 at 11:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Safari 26.6 or later, or update iOS 26.6 and iPadOS 26.6
  • Install macOS Tahoe 26.6 and update tvOS, visionOS, and watchOS to 26.6 or later
  • Ensure devices run the latest operating system and app updates to maintain the patch

Generated by OpenCVE AI on August 12, 2026 at 11:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Leading to Safari Crash via Malicious Web Content
Weaknesses CWE-416

Tue, 04 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Crash in Safari and Apple Web Browsers
Weaknesses CWE-416

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Crash in Safari and Apple Web Browsers
Weaknesses CWE-416

Tue, 28 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T18:40:21.814Z

Reserved: 2026-07-20T18:09:35.084Z

Link: CVE-2026-64718

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:10.753

Modified: 2026-07-29T19:55:37.530

Link: CVE-2026-64718

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T11:15:03Z

Weaknesses