Junglewise Threat Intelligence

CVE-2026-64784: Apple Safari out-of-bounds access in WebKit

CVE-2026-64784 · Severity: medium · CVSS 4.3 · Published 2026-08-17

Technologies: Apple Safari, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Safari is a web browser used by millions to browse the internet on Apple devices. A flaw in the browser's WebKit engine allows attackers to craft malicious web pages that cause Safari to unexpectedly crash when visited. While this doesn't directly compromise user data, it can disrupt browsing and potentially be a stepping stone for more sophisticated attacks.

Technical details

CVE-2026-64784 is an out-of-bounds access vulnerability in Apple's WebKit rendering engine. The issue occurs when Safari processes maliciously crafted web content, resulting in an unexpected crash due to improved bounds checking that was not originally in place. The attack vector is network-based and requires user interaction (visiting a malicious website). No authentication is required. An attacker can achieve a denial-of-service condition by crashing the Safari browser. The vulnerability is fixed in Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27.

Affected products

  • Apple Safari before 26.6.1
  • Apple iOS before 18.7.10 and 26.6.1
  • Apple iPadOS before 18.7.10 and 26.6.1
  • Apple macOS Tahoe before 26.6.2
  • Apple visionOS before 27

Timeline

  • 2026-08-17: disclosed
  • 2026-08-17: patched

References

Related threats