Description
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Published: 2026-08-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Safari's state management, before being addressed through improved state handling in later releases, allows maliciously crafted web content to trigger an unexpected crash. This crash results in a denial‑of‑service that can disrupt user sessions. The vulnerability originates from improper input handling that bypasses expected bounds or validation checks, leading to an unrecoverable error within the browser process.

Affected Systems

Affected systems include Apple iOS and iPadOS devices running versions prior to iOS 18.7.10 or iOS 26.6.1, and macOS Tahoe versions prior to 26.6.2. The vulnerability is present in Safari integrated with these operating systems.

Risk and Exploitability

The CVSS score is 4.3. The EPSS score is less than 1%, which indicates a very low probability of exploitation. No active exploitation evidence is reported and the impact is limited to a Safari crash, so the overall risk is considered moderate. The vulnerability can be exploited by delivering specially crafted web content, such as through a link, an embedded frame, or a malicious website, making it a remote threat that does not require local privileges.

Generated by OpenCVE AI on August 27, 2026 at 02:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest iOS/iPadOS update (18.7.10 or newer) on all affected devices.
  • Install the latest macOS Tahoe update (26.6.2 or newer) on all affected Macs.
  • After applying the updates, restart Safari to ensure the state changes take effect and avoid loading untrusted web content until the system is fully up to date.

Generated by OpenCVE AI on August 27, 2026 at 02:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Safari Crash from Improper State Management webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
Weaknesses CWE-120
References
Metrics threat_severity

None

threat_severity

Important


Tue, 18 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Safari Crash from Improper State Management

Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 18 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Safari State Management Crash from Malicious Web Content
Weaknesses CWE-122
CWE-20

Tue, 18 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash. This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Safari State Management Crash from Malicious Web Content
Weaknesses CWE-122
CWE-20

Mon, 17 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-18T17:59:25.529Z

Reserved: 2026-07-22T00:45:02.635Z

Link: CVE-2026-65333

cve-icon Vulnrichment

Updated: 2026-08-18T13:20:26.858Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-17T22:17:24.233

Modified: 2026-08-18T18:52:57.027

Link: CVE-2026-65333

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-17T21:29:42Z

Links: CVE-2026-65333 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T02:15:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')