Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected process termination.
Published: 2026-08-17
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free condition that can cause an unexpected process termination when maliciously crafted web content is processed. This results in a denial of service type impact, as the affected process crashes, but does not provide an attacker with code execution or elevated privileges.

Affected Systems

Apple devices running iOS, iPadOS, or macOS are affected. The issue is fixed in iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2; all older releases remain vulnerable.

Risk and Exploitability

Exact CVSS and EPSS scores are not available, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be through malicious web content—e.g., pages served over HTTP/HTTPS or embedded in a web view—indicating that the threat originates from content accessed by users. Exploitation could be automated but would likely be limited to triggering application crashes rather than gaining further foothold on the system.

Generated by OpenCVE AI on August 17, 2026 at 23:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to iOS 26.6.1, iPadOS 26.6.1, or macOS Tahoe 26.6.2 to receive the memory‑management fix.
  • If an update cannot be applied immediately, limit exposure by restricting access to untrusted web content, for example through network filtering or browser sandboxing.
  • Monitor device logs or crash reports for unexpected termination events that may indicate attempted exploitation.

Generated by OpenCVE AI on August 17, 2026 at 23:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Causing Unexpected Process Termination in Apple Web Content Rendering
Weaknesses CWE-416

Mon, 17 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected process termination.
References

Subscriptions

Apple Ios And Ipados Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:30:33.068Z

Reserved: 2026-07-20T18:11:03.398Z

Link: CVE-2026-64787

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T22:17:23.377

Modified: 2026-08-17T22:17:23.377

Link: CVE-2026-64787

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T23:30:04Z

Weaknesses