Junglewise Threat Intelligence

CVE-2026-20664: Apple and Red Hat memory corruption in web content processing

CVE-2026-20664 · Severity: medium · CVSS 4.3 · Published 2026-03-25

Technologies: Apple macOS, Apple Safari, Apple Iphone Os, Apple Visionos, Apple iPadOS, Red Hat Enterprise Linux. Vendors: Apple, Red Hat.

Executive brief

Apple and Red Hat products are affected by a memory handling vulnerability when processing web content. For users, this means that visiting a maliciously crafted website could cause their web browser or device to crash unexpectedly. While primarily an availability issue, such crashes can disrupt operations and lead to unsaved data loss.

Technical details

A memory handling vulnerability, identified as a buffer overflow or out-of-bounds write (CWE-120, CWE-787), exists in how various Apple operating systems and Red Hat Enterprise Linux components process web content. The issue is triggered when a user visits a maliciously crafted webpage, leading to an unexpected process crash. While CISA-ADP rates this as a medium severity availability issue (CVSS 4.3), Red Hat has assigned a higher severity (CVSS 8.8) suggesting potential for broader impact in their environment. The vulnerability has been addressed in Safari 26.4, iOS/iPadOS 26.4, macOS Tahoe 26.4, and visionOS 26.4 through improved memory handling.

Affected products

  • Apple Safari 26.4
  • Apple iOS 26.4
  • Apple iPadOS 26.4
  • Apple macOS Tahoe 26.4
  • Apple visionOS 26.4
  • Red Hat Enterprise Linux 7, 8, 9

Timeline

  • 2026-03-25: disclosed: Initial publication date
  • 2026-03-25: patched: Fixed in Apple OS updates version 26.4

References

Related threats