Description
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Published: 2026-08-17
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Browser Crash)
Action: Apply Patch
AI Analysis

Impact

A memory corruption vulnerability in Safari occurs because of improper locking when processing maliciously crafted web content. The flaw can corrupt shared memory during parsing, which can cause Safari to crash unexpectedly. The result is a denial‑of‑service in the browser, with no disclosed privilege escalation or data exfiltration. This is a race condition and process synchronization flaw (CWE-362, CWE-667).

Affected Systems

Apple devices running Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27 are affected. The issue is present in Safari on iOS, iPadOS, macOS, and visionOS until the versions above are installed.

Risk and Exploitability

The CVSS score of 3.1 and the EPSS score of less than 1% indicate a low severity and a low probability of exploitation. The vulnerability is not listed in CISA KEV. Attackers would typically need to deliver malicious web content that triggers the parsing problem, which generally requires the victim to visit a compromised or malicious site. No privilege escalation or confidentiality breach is possible from this vulnerability based on the available information.

Generated by OpenCVE AI on September 21, 2026 at 07:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest OS updates that include Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27.
  • Ensure Safari stays updated with the patched releases.
  • Until the update is available, avoid visiting sites that may serve malicious content and restart Safari if it crashes.

Generated by OpenCVE AI on September 21, 2026 at 07:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash. A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Thu, 27 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Safari Memory Corruption Crash Vulnerability webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
Weaknesses CWE-667
References
Metrics threat_severity

None

threat_severity

Important


Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Safari Memory Corruption Crash Vulnerability

Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 18 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash. A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Title Memory Corruption Leading to Safari Crash via Improper Locking
Weaknesses CWE-416
CWE-787
References

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Memory Corruption Leading to Safari Crash via Improper Locking
Weaknesses CWE-416
CWE-787

Mon, 17 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:47:26.113Z

Reserved: 2026-07-20T18:10:53.025Z

Link: CVE-2026-64779

cve-icon Vulnrichment

Updated: 2026-08-18T13:15:35.895Z

cve-icon NVD

Status : Modified

Published: 2026-08-17T22:17:22.873

Modified: 2026-09-14T21:17:15.533

Link: CVE-2026-64779

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-17T21:29:15Z

Links: CVE-2026-64779 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T07:30:08Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-667

    Improper Locking