Junglewise Threat Intelligence

CVE-2026-64778: Apple Safari information disclosure via malicious website

CVE-2026-64778 · Severity: medium · CVSS 6.5 · Published 2026-08-17

Technologies: Apple Tvos, Apple macOS, Apple Safari, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Safari is Apple's web browser used across Mac, iPhone, and iPad devices. A malicious website can leak sensitive user data through improved state management vulnerabilities. This could expose personal information to attackers without user awareness or intervention beyond visiting a compromised site.

Technical details

The vulnerability is an information disclosure issue in WebKit (Safari's rendering engine) triggered by visiting a maliciously crafted website. The root cause involves improper state management in Safari's web content processing. An unauthenticated, network-adjacent attacker can craft a malicious webpage to trigger the vulnerability without requiring user interaction beyond visiting the site. Successful exploitation results in leakage of sensitive user data. The issue was addressed with improved state management checks in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and later OS versions.

Affected products

  • Apple Safari before 26.6.1
  • Apple iOS before 26.6.1
  • Apple iPadOS before 26.6.1
  • Apple macOS Tahoe before 26.6.2
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-08-17: disclosed
  • 2026-08-17: patched

References

Related threats