Junglewise Threat Intelligence

CVE-2026-64787: Apple Safari and WebKit use-after-free in web content processing

CVE-2026-64787 · Severity: medium · CVSS 6.5 · Published 2026-08-17

Technologies: Apple Tvos, Apple macOS, Apple Safari, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Safari and the WebKit browser engine contain a use-after-free memory vulnerability that can be triggered by viewing maliciously crafted web content. An attacker can exploit this to crash the browser or potentially execute arbitrary code, affecting Safari users on Mac, iPhone, and iPad devices. The vulnerability is fixed in Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, and later versions.

Technical details

A use-after-free vulnerability exists in WebKit's memory management, allowing an attacker to access memory that has been freed. The vulnerability is triggered by processing maliciously crafted web content, which can lead to unexpected process termination (denial of service) or potentially memory corruption. The attack requires no special privilege or authentication—simply visiting a malicious webpage is sufficient. The vulnerability affects Safari and all browsers built on WebKit (iOS Safari, iPadOS Safari). Apple has patched the issue with improved memory management in Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, macOS Tahoe 26.6.2, and corresponding later releases across tvOS, visionOS, and watchOS.

Affected products

  • Apple Safari before 26.6.1
  • Apple iOS before 18.7.10 and before 26.6.1
  • Apple iPadOS before 18.7.10 and before 26.6.1
  • Apple macOS Tahoe before 26.6.2
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-08-17: disclosed: Published in Apple security advisory
  • 2026-08-17: patched: Fixed in Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27

References

Related threats