Description
An integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.
Published: 2026-09-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption
Action: Patch Now
AI Analysis

Impact

An integer overflow was identified in the processing of web content on several Apple platforms. When a user views maliciously crafted web content, the overflow can lead to memory corruption, potentially causing a system crash or facilitating other types of exploitation.

Affected Systems

The vulnerability affects Apple Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS. Specifically, Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27 include the fix. Users running earlier versions of these products remain vulnerable until they upgrade to a patched release.

Risk and Exploitability

The flaw scores 8.8 on CVSS, indicating a high severity. The EPSS score is < 1%, indicating a very low probability of exploitation in the wild. It is not included in the CISA KEV catalog. Attackers can trigger the integer overflow by delivering maliciously crafted web content to a vulnerable browser or application, potentially causing memory corruption and leading to denial of service or arbitrary code execution, depending on the attacker’s skill and system context. Because the flaw can be activated simply by browsing a malicious site, it is remotely exploitable without local privileges.

Generated by OpenCVE AI on September 20, 2026 at 21:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest security updates: Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27.
  • Keep automatic system updates enabled to receive any subsequent security patches promptly.
  • Review Apple security advisories regularly and contact Apple support for devices that cannot be updated.

Generated by OpenCVE AI on September 20, 2026 at 21:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Web Content Processing Leading to Memory Corruption

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Integer overflow in Safari and Apple web platforms leads to memory corruption

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title Integer overflow in Safari and Apple web platforms leads to memory corruption
Weaknesses CWE-680

Tue, 15 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T03:56:38.836Z

Reserved: 2026-07-22T00:46:44.572Z

Link: CVE-2026-65390

cve-icon Vulnrichment

Updated: 2026-09-15T17:46:33.067Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:22.767

Modified: 2026-09-16T14:12:52.793

Link: CVE-2026-65390

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:30:06Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound

  • CWE-680

    Integer Overflow to Buffer Overflow