Executive brief
Safari is Apple's web browser used by millions to browse the internet. A malicious website could cause Safari to unexpectedly crash by sending specially crafted web content, resulting in denial of service and potential user frustration or data loss.
Technical details
CVE-2026-64780 is an out-of-bounds access vulnerability in Safari's WebKit rendering engine. The issue occurs when processing maliciously crafted web content, allowing an attacker to trigger an unexpected Safari crash. No authentication is required—the attack is triggered simply by visiting a malicious website. The vulnerability has been addressed with improved bounds checking. Patches are available in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27.
Affected products
- Apple Safari before 26.6.1
- Apple iOS before 26.6.1
- Apple iPadOS before 26.6.1
- Apple macOS Tahoe before 26.6.2
- Apple visionOS before 27
Timeline
- 2026-08-17: disclosed
- 2026-08-17: patched