Description
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Published: 2026-07-27
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A memory corruption issue, classified as CWE-119 and CWE-120, was addressed with improved state management in Safari. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, and watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. The flaw causes an application failure rather than arbitrary code execution, resulting in a denial‑of‑service impact.

Affected Systems

The flaw affects Safari and its core web rendering components on macOS, iOS, iPadOS, visionOS, and watchOS. Devices running any of these platforms with versions earlier than Safari 26.6, iOS 18.7.10 or 26.6, iPadOS 18.7.10 or 26.6, macOS Tahoe 26.6, visionOS 26.6, or watchOS 26.6 are vulnerable. Apple has released simultaneous fixes: Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, and watchOS 26.6.

Risk and Exploitability

The EPSS score is < 1%, indicating a very low likelihood of exploitation, but the CVSS score of 8.8 classifies it as high severity. No public exploitation data is known and the flaw is not listed in the CISA KEV catalog. The attack vector is inferred to be a remote attacker delivering malicious web content that renders in Safari. Because the flaw leads only to a crash, exploitation risk is limited to denial of service and there are no known mechanisms for code execution or persistent compromise. The vulnerability therefore represents a high risk that can be mitigated by upgrading to the fixed releases.

Generated by OpenCVE AI on August 22, 2026 at 11:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Safari, iOS, iPadOS, macOS, visionOS, or watchOS to version 26.6 or later
  • Configure the system to receive automatic software updates
  • Monitor for unexpected Safari crashes and report anomalous web content to Apple

Generated by OpenCVE AI on August 22, 2026 at 11:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6463-1 webkit2gtk security update
Ubuntu USN Ubuntu USN USN-8703-1 WebKitGTK vulnerabilities
History

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Safari Crash via Memory Corruption webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
Weaknesses CWE-120
References
Metrics threat_severity

None

threat_severity

Important


Tue, 18 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Safari Crash via Memory Corruption

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption Crash Vulnerability in Apple Web Browsers

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption Crash Vulnerability in Apple Web Browsers
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Safari Visionos Watchos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:31:15.629Z

Reserved: 2026-07-20T18:10:30.633Z

Link: CVE-2026-64757

cve-icon Vulnrichment

Updated: 2026-07-28T15:47:50.418Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:14.120

Modified: 2026-08-17T22:17:20.780

Link: CVE-2026-64757

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-20T00:00:00Z

Links: CVE-2026-64757 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T12:00:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')