Junglewise Threat Intelligence

CVE-2026-43795: Apple Safari WebKit memory handling issue

CVE-2026-43795 · Severity: medium · CVSS 4.3 · Published 2026-08-17

Technologies: Apple macOS, Apple Safari, Apple iPadOS. Vendors: Apple.

Executive brief

Apple Safari, the web browser used to access the internet on Apple devices, contains a memory handling vulnerability in its WebKit rendering engine. A user who visits a malicious website could experience an unexpected browser crash, potentially disrupting their browsing session.

Technical details

CVE-2026-43795 is a memory handling vulnerability in WebKit (Safari's rendering engine) triggered by processing maliciously crafted web content. The issue was addressed with improved memory handling. The attack vector is network-based, requiring only that a user visit a malicious website; no authentication or special user interaction beyond normal browsing is required. An attacker can cause an unexpected Safari crash, leading to a denial of service. The vulnerability has been patched in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2.

Affected products

  • Apple Safari prior to 26.6.1
  • Apple iOS prior to 26.6.1
  • Apple iPadOS prior to 26.6.1
  • Apple macOS Tahoe prior to 26.6.2

Timeline

  • 2026-08-17: disclosed
  • 2026-08-17: patched: Fixed in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2

References

Related threats