Junglewise Threat Intelligence

CVE-2026-43794: Apple WebKit memory corruption in web content processing

CVE-2026-43794 · Severity: high · CVSS 8.8 · Published 2026-08-17

Technologies: Apple Tvos, Apple Safari, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

WebKit, the browser engine used in Safari and other Apple applications, contains a memory corruption vulnerability that can be triggered by viewing maliciously crafted web content. An attacker could exploit this flaw to crash Safari, corrupt system memory, or potentially execute arbitrary code, affecting users across iPhones, iPads, Macs, and other Apple devices.

Technical details

CVE-2026-43794 is a memory corruption vulnerability in Apple's WebKit engine, addressed through improved memory handling. The vulnerability is triggered when processing maliciously crafted web content and does not require user interaction beyond opening a malicious webpage. The flaw affects WebKit across multiple Apple platforms including Safari, iOS, iPadOS, and macOS. The vulnerability has been patched in Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27. No known active exploitation in the wild has been reported.

Affected products

  • Apple Safari before 26.6.1
  • Apple iOS before 18.7.10 and before 26.6.1
  • Apple iPadOS before 18.7.10 and before 26.6.1
  • Apple macOS Tahoe before 26.6.2
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-08-17: disclosed: CVE-2026-43794 disclosed and patched
  • 2026-08-17: patched: Fixes released in Safari 26.6.1, iOS/iPadOS versions, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27

References

Related threats