Junglewise Threat Intelligence

CVE-2026-64757: Apple Safari memory corruption in web content processing

CVE-2026-64757 · Severity: info · Published 2026-07-27

Technologies: Apple Safari, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A memory corruption vulnerability exists in Apple's Safari web browser and various operating systems including iOS, macOS, and watchOS. If a user visits a website containing specially crafted malicious content, it could cause the browser to crash unexpectedly. This issue affects the stability of the device and could potentially be used as a stepping stone for further attacks.

Technical details

A memory corruption vulnerability was identified in Apple Safari and multiple Apple operating systems (iOS, iPadOS, macOS, visionOS, and watchOS). The flaw is rooted in improper state management when processing web content. An attacker can exploit this by hosting or delivering maliciously crafted web content that, when processed by the target's browser, triggers the memory corruption. While the primary reported impact is an unexpected Safari crash (denial of service), memory corruption issues often carry a risk of arbitrary code execution. The issue was addressed by improving state management in Safari 26.6 and the corresponding OS updates.

Affected products

  • Apple Safari Before 26.6
  • Apple iOS and iPadOS Before 26.6
  • Apple macOS Tahoe Before 26.6
  • Apple visionOS Before 26.6
  • Apple watchOS Before 26.6

Timeline

  • 2026-07-27: disclosed: Initial advisory publication by Apple.
  • 2026-07-27: patched: Fixed in Safari 26.6 and related OS versions.

References

Related threats