Executive brief
WebKit, the browser engine used in Safari and other Apple applications, contains a memory corruption vulnerability that can be triggered by viewing maliciously crafted web content. An attacker could exploit this flaw to crash Safari, corrupt system memory, or potentially execute arbitrary code, affecting users across iPhones, iPads, Macs, and other Apple devices.
Technical details
CVE-2026-43794 is a memory corruption vulnerability in Apple's WebKit engine, addressed through improved memory handling. The vulnerability is triggered when processing maliciously crafted web content and does not require user interaction beyond opening a malicious webpage. The flaw affects WebKit across multiple Apple platforms including Safari, iOS, iPadOS, and macOS. The vulnerability has been patched in Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27. No known active exploitation in the wild has been reported.
Affected products
- Apple Safari before 26.6.1
- Apple iOS before 18.7.10 and before 26.6.1
- Apple iPadOS before 18.7.10 and before 26.6.1
- Apple macOS Tahoe before 26.6.2
- Apple tvOS before 27
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-08-17: disclosed: CVE-2026-43794 disclosed and patched
- 2026-08-17: patched: Fixes released in Safari 26.6.1, iOS/iPadOS versions, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27