Description
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Published: 2026-08-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Updates
AI Analysis

Impact

An out‑of‑bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash. The flaw causes a local denial of service by terminating the browser process, but does not permit code execution or privilege escalation.

Affected Systems

The affected products are Apple’s Safari running on iOS, iPadOS, macOS, and visionOS. The CVE notes that the issue is fixed in iOS 18.7.10 and 26.6.1, iPadOS 18.7.10 and 26.6.1, and visionOS 27. Versions prior to these remain at risk.

Risk and Exploitability

The CVSS score of 4.3 reflects moderate impact, while the EPSS score of less than 1% indicates a very low likelihood of exploitation. The exploit requires delivery of malicious web content via Safari, typically through a phishing or malicious website, making the threat realistic but limited. The vulnerability is not catalogued in CISA’s KEV list, further suggesting minimal pressure to exploit.

Generated by OpenCVE AI on September 21, 2026 at 06:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest iOS, visionOS releases that include the Safari fix (iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27) – this patch eliminates the out‑of‑bounds read and buffer over‑read vulnerabilities (CWE‑120, CWE‑125, CWE‑787).
  • If a device cannot be updated immediately, limit Safari usage to trusted sites or disable the browser until the patch is applied.
  • Keep new advisories and follow any temporary work‑around guidance that may be issued.

Generated by OpenCVE AI on September 21, 2026 at 06:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash. An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Thu, 27 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
Weaknesses CWE-120
References
Metrics threat_severity

None

threat_severity

Important


Tue, 18 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
Apple safari
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os
Apple safari

Tue, 18 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash. An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Title Out‑of‑Bounds Access in Safari Leading to Crash
References

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}


Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Access in Safari Leading to Crash
Weaknesses CWE-125

Mon, 17 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Safari
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:49:55.029Z

Reserved: 2026-07-20T18:11:03.397Z

Link: CVE-2026-64784

cve-icon Vulnrichment

Updated: 2026-08-18T13:33:46.493Z

cve-icon NVD

Status : Modified

Published: 2026-08-17T22:17:23.273

Modified: 2026-09-14T21:17:16.223

Link: CVE-2026-64784

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-17T21:30:45Z

Links: CVE-2026-64784 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T07:00:08Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

  • CWE-125

    Out-of-bounds Read

  • CWE-787

    Out-of-bounds Write