Description
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Published: 2026-08-17
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A memory corruption vulnerability in Safari, caused by improper locking, is triggered by maliciously crafted web content and may produce an unexpected crash. Apple has addressed the issue with improved locking and released fix versions Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2. The crash leads to denial of service but does not provide arbitrary code execution.

Affected Systems

Apple devices running Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2 are affected. Users should verify their OS and Safari version and upgrade to a release that includes the fix.

Risk and Exploitability

The CVSS score of 3.1 indicates a low severity indicator. With an EPSS score of <1% and no listing in KEV, the probability of exploitation remains low. Based on the description, it is inferred that the vulnerability can be triggered by delivering malicious web content to a victim’s Safari browser, leading to a crash that denies service. Attackers would need to persuade the user to load the malicious content.

Generated by OpenCVE AI on August 27, 2026 at 02:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, or macOS Tahoe 26.6.2, which contain the security fix.
  • Keep Safari updated to the latest version that includes the relevant patch.
  • Until the update can be applied, avoid visiting sites known to supply malicious content and restart Safari if a crash occurs.

Generated by OpenCVE AI on August 27, 2026 at 02:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Safari Memory Corruption Crash Vulnerability webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
Weaknesses CWE-667
References
Metrics threat_severity

None

threat_severity

Important


Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Safari Memory Corruption Crash Vulnerability

Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 18 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash. A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Title Memory Corruption Leading to Safari Crash via Improper Locking
Weaknesses CWE-416
CWE-787
References

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Memory Corruption Leading to Safari Crash via Improper Locking
Weaknesses CWE-416
CWE-787

Mon, 17 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-18T17:59:19.629Z

Reserved: 2026-07-20T18:10:53.025Z

Link: CVE-2026-64779

cve-icon Vulnrichment

Updated: 2026-08-18T13:15:35.895Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-17T22:17:22.873

Modified: 2026-08-18T18:54:29.797

Link: CVE-2026-64779

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-17T21:29:15Z

Links: CVE-2026-64779 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T02:15:04Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-667

    Improper Locking