Junglewise Threat Intelligence

CVE-2026-64779: Apple Safari WebKit memory corruption with improved locking

CVE-2026-64779 · Severity: low · CVSS 3.1 · Published 2026-08-17

Technologies: Apple Safari, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Safari is a web browser used by millions to access websites on Apple devices. A memory corruption bug in Safari's web engine (WebKit) can crash the browser when visiting maliciously crafted websites, potentially disrupting user productivity and, in rare cases, could be exploited for more serious attacks. Apple has released patches to address this issue.

Technical details

This vulnerability is a memory corruption issue in WebKit, the rendering engine used by Safari. The bug stems from improper locking mechanisms that fail to properly synchronize access to shared memory, allowing race conditions during malicious web content processing. The attack vector is network-based: an attacker can craft a malicious webpage that, when visited by a Safari user, triggers the memory corruption. No authentication or special user interaction beyond normal web browsing is required. Successful exploitation leads to an unexpected Safari crash and potential denial of service. The vulnerability has been patched in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27, with fixes available as of August 17, 2026.

Affected products

  • Apple Safari before 26.6.1
  • Apple iOS before 26.6.1
  • Apple iPadOS before 26.6.1
  • Apple macOS Tahoe before 26.6.2
  • Apple visionOS before 27

Timeline

  • 2026-08-17: disclosed
  • 2026-08-17: patched: Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27

References

Related threats