Executive brief
Apple Safari, the web browser used to access the internet on Apple devices, contains a memory handling vulnerability in its WebKit rendering engine. A user who visits a malicious website could experience an unexpected browser crash, potentially disrupting their browsing session.
Technical details
CVE-2026-43795 is a memory handling vulnerability in WebKit (Safari's rendering engine) triggered by processing maliciously crafted web content. The issue was addressed with improved memory handling. The attack vector is network-based, requiring only that a user visit a malicious website; no authentication or special user interaction beyond normal browsing is required. An attacker can cause an unexpected Safari crash, leading to a denial of service. The vulnerability has been patched in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2.
Affected products
- Apple Safari prior to 26.6.1
- Apple iOS prior to 26.6.1
- Apple iPadOS prior to 26.6.1
- Apple macOS Tahoe prior to 26.6.2
Timeline
- 2026-08-17: disclosed
- 2026-08-17: patched: Fixed in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2