Description
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Published: 2026-08-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via unexpected Safari crash
Action: Immediate Patch
AI Analysis

Impact

An unexpected Safari crash can be triggered by processing maliciously crafted web content. The flaw results from insufficient state management within Safari’s web rendering engine, causing a buffer overrun or overread; the impact is denial of service because the browser terminates abruptly, disrupting user sessions. This weakness aligns with CWE-119 and CWE-120. Based on the description, the likely attack vector is the delivery of malicious web content, such as a crafted link or an embedded frame, that causes the crash.

Affected Systems

Apple iOS and iPadOS devices running any version older than the patched releases of iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, or iPadOS 26.6.1 are affected, as are macOS systems older than Tahoe 26.6.2 and visionOS devices before version 27. These platforms integrate Safari and the vulnerable web rendering engine, so any device on those operating systems can experience a crash when loading untrusted web pages.

Risk and Exploitability

The CVSS base score is 4.3, indicating moderate severity. The EPSS score is less than 1 %, showing a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can trigger the crash remotely by delivering malicious web content via a link, an embedded frame, or a malicious website. No local privileges or additional conditions are required, making it a straightforward remote threat that results only in a browser crash.

Generated by OpenCVE AI on September 21, 2026 at 07:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest updates for iOS 18.7.10, iPadOS 18.7.10, macOS Tahoe 26.6.2, and visionOS 27 on all affected devices.
  • After the update, restart Safari to ensure state changes take effect.
  • Until the update is fully applied, avoid loading untrusted web content that may trigger the crash.

Generated by OpenCVE AI on September 21, 2026 at 07:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash. This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Thu, 27 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Safari Crash from Improper State Management webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
Weaknesses CWE-120
References
Metrics threat_severity

None

threat_severity

Important


Tue, 18 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Safari Crash from Improper State Management

Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 18 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Safari State Management Crash from Malicious Web Content
Weaknesses CWE-122
CWE-20

Tue, 18 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash. This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Safari State Management Crash from Malicious Web Content
Weaknesses CWE-122
CWE-20

Mon, 17 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:48:09.329Z

Reserved: 2026-07-22T00:45:02.635Z

Link: CVE-2026-65333

cve-icon Vulnrichment

Updated: 2026-08-18T13:20:26.858Z

cve-icon NVD

Status : Modified

Published: 2026-08-17T22:17:24.233

Modified: 2026-09-14T21:17:17.530

Link: CVE-2026-65333

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-17T21:29:42Z

Links: CVE-2026-65333 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T07:15:07Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')