Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected process termination.
Published: 2026-08-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free condition that occurs when Apple WebKit processes maliciously crafted web content. The flaw arises from improper memory management, allowing an attacker to trigger an unexpected termination of the process handling the content. While this results in a denial‑of‑service type impact by crashing the affected application, it does not grant an attacker code execution or elevated privileges.

Affected Systems

Apple devices running Safari, iOS, iPadOS, or macOS are affected. The issue is fixed in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2; all older releases remain vulnerable.

Risk and Exploitability

The measured CVSS score is 6.5, and the EPSS score is < 1%. The vulnerability is not listed in CISA KEV. The attack vector is inferred to be through malicious web content—e.g., pages served over HTTP/HTTPS or embedded in a web view—indicating that the threat originates from content accessed by users. Exploitation could be automated but would likely be limited to triggering application crashes rather than gaining further foothold on the system.

Generated by OpenCVE AI on August 18, 2026 at 20:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to iOS 26.6.1, iPadOS 26.6.1, or macOS Tahoe 26.6.2 to receive the memory‑management fix.
  • If an update cannot be applied immediately, limit exposure by restricting access to untrusted web content, for example through network filtering or browser sandboxing.
  • Monitor device logs or crash reports for unexpected termination events that may indicate attempted exploitation.

Generated by OpenCVE AI on August 18, 2026 at 20:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8703-1 WebKitGTK vulnerabilities
History

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Causes Application Crash in Apple WebKit webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination
References
Metrics threat_severity

None

threat_severity

Important


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Causes Application Crash in Apple WebKit

Tue, 18 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
Apple safari
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os
Apple safari

Tue, 18 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected process termination. A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected process termination.
References

Tue, 18 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Causing Unexpected Process Termination in Apple Web Content Rendering

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Causing Unexpected Process Termination in Apple Web Content Rendering
Weaknesses CWE-416

Mon, 17 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected process termination.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Safari
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-18T17:59:30.727Z

Reserved: 2026-07-20T18:11:03.398Z

Link: CVE-2026-64787

cve-icon Vulnrichment

Updated: 2026-08-18T13:27:18.919Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-17T22:17:23.377

Modified: 2026-08-18T19:56:38.177

Link: CVE-2026-64787

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-20T00:00:00Z

Links: CVE-2026-64787 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T21:00:04Z

Weaknesses