Description
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Published: 2026-08-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Safari crash)
Action: Patch
AI Analysis

Impact

Processing maliciously crafted web content may cause Safari to crash due to a flaw in state management. The fault does not give an attacker code execution or data exfiltration, but terminates the browser, leading to a denial‑of‑service condition for the affected user session. The weakness is linked to improper state handling (CWE‑703) and a buffer management issue (CWE‑120).

Affected Systems

Apple’s Safari browser on iOS, iPadOS, macOS and visionOS is affected. The fix is incorporated in Safari 26.6.1, iOS 18.7.10 and 26.6.1, iPadOS 18.7.10 and 26.6.1, macOS Tahoe 26.6.2, and visionOS 27.

Risk and Exploitability

The attack vector is inferred to be the delivery of malicious web content over the internet, which triggers the crash when rendered by Safari. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 4.3 reflects moderate severity for availability disruption; the risk remains moderate for end‑users until a patch is applied.

Generated by OpenCVE AI on September 21, 2026 at 06:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest iOS update (18.7.10 or 26.6.1) that includes the Safari 26.6.1 patch.
  • Install the latest macOS update (Tahoe 26.6.2) to update Safari to the protected version.
  • Install the latest visionOS update (27) to receive the crash fix.
  • Restart Safari after the operating system update to ensure the patch is active.

Generated by OpenCVE AI on September 21, 2026 at 06:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash. This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Thu, 27 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
Weaknesses CWE-120
References
Metrics threat_severity

None

threat_severity

Important


Tue, 18 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Safari Crash from Maliciously Crafted Web Content Leading to Denial of Service
First Time appeared Apple ipados
Apple iphone Os
Apple safari
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os
Apple safari

Tue, 18 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Safari Crash from Maliciously Crafted Web Content Leading to Denial of Service

Tue, 18 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash. This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Tue, 18 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Title Safari Web Content Crash Leading to Denial of Service
Weaknesses CWE-676
CWE-682

Tue, 18 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-703
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Safari Web Content Crash Leading to Denial of Service
Weaknesses CWE-676
CWE-682

Mon, 17 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Safari
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:51:56.645Z

Reserved: 2026-07-22T00:45:02.635Z

Link: CVE-2026-65331

cve-icon Vulnrichment

Updated: 2026-08-18T12:55:00.491Z

cve-icon NVD

Status : Modified

Published: 2026-08-17T22:17:24.040

Modified: 2026-09-14T21:17:17.190

Link: CVE-2026-65331

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-17T21:31:37Z

Links: CVE-2026-65331 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T07:00:08Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

  • CWE-703

    Improper Check or Handling of Exceptional Conditions