Junglewise Threat Intelligence

CVE-2026-64715: Apple WebKit use-after-free in Safari

CVE-2026-64715 · Severity: medium · CVSS 6.5 · Published 2026-08-17

Technologies: Apple Tvos, Apple Safari, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Safari and WebKit-based browsers contain a use-after-free memory vulnerability that can be triggered by processing maliciously crafted web content. An attacker can exploit this flaw by hosting malicious web pages, causing Safari to crash unexpectedly and disrupting user productivity. While the primary impact is denial of service, use-after-free vulnerabilities can potentially lead to memory corruption or code execution in some cases.

Technical details

A use-after-free vulnerability exists in WebKit's memory management. The flaw occurs when maliciously crafted web content is processed, causing the browser to access memory that has already been freed. The vulnerability is triggered when users visit or are redirected to a malicious website; no authentication or special user interaction beyond clicking a link is required. An attacker can reliably crash Safari or Safari-based applications. The vulnerability has been addressed with improved memory management and is patched in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2.

Affected products

  • Apple Safari before 26.6.1
  • Apple iOS before 26.6.1 and 18.7.10
  • Apple iPadOS before 26.6.1 and 18.7.10
  • Apple macOS Tahoe before 26.6.2
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-08-17: disclosed: CVE-2026-64715 published and security update released
  • 2026-08-17: patched: Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27

References

Related threats