Description
This issue was addressed through improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Published: 2026-08-17
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A weakness in Safari’s state management allows an attacker to cause the browser to crash when it processes maliciously crafted web content. The crash results in a denial of service that can temporarily interrupt web browsing, and may require a device restart before normal operation resumes.

Affected Systems

The vulnerability affects Apple devices running iOS versions prior to 26.6.1, iPadOS versions prior to 26.6.1, and macOS Tahoe versions prior to 26.6.2. All versions of Safari bundled with these operating systems are impacted.

Risk and Exploitability

The vulnerability is exploitable via any web page that includes specially crafted content. The risk is a local denial of service that can be triggered remotely by visiting a malicious site; the excerpt does not provide a CVSS score, and EPSS data is unavailable, so the quantitative risk level cannot be precisely assessed. The issue is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on August 18, 2026 at 00:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest operating system updates, which include Safari fixes to address the reported state management issue.
  • Until updates are installed, avoid browsing untrusted or suspicious websites that may contain malicious content designed to trigger the crash.
  • Configure device automatic updates to ensure timely receipt of future security patches, and verify that the system shows the correct OS version after installation.

Generated by OpenCVE AI on August 18, 2026 at 00:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Safari Crash via Malformed Web Content Leading to Denial of Service
First Time appeared Apple
Apple ios And Ipados
Apple macos
Weaknesses CWE-20
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Subscriptions

Apple Ios And Ipados Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:31:25.582Z

Reserved: 2026-07-22T00:45:50.324Z

Link: CVE-2026-65351

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T22:17:25.580

Modified: 2026-08-17T22:17:25.580

Link: CVE-2026-65351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T00:15:03Z

Weaknesses
  • CWE-20

    Improper Input Validation