Executive brief
Safari and the WebKit browser engine contain a use-after-free memory vulnerability that can be triggered by viewing maliciously crafted web content. An attacker can exploit this to crash the browser or potentially execute arbitrary code, affecting Safari users on Mac, iPhone, and iPad devices. The vulnerability is fixed in Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, and later versions.
Technical details
A use-after-free vulnerability exists in WebKit's memory management, allowing an attacker to access memory that has been freed. The vulnerability is triggered by processing maliciously crafted web content, which can lead to unexpected process termination (denial of service) or potentially memory corruption. The attack requires no special privilege or authentication—simply visiting a malicious webpage is sufficient. The vulnerability affects Safari and all browsers built on WebKit (iOS Safari, iPadOS Safari). Apple has patched the issue with improved memory management in Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, macOS Tahoe 26.6.2, and corresponding later releases across tvOS, visionOS, and watchOS.
Affected products
- Apple Safari before 26.6.1
- Apple iOS before 18.7.10 and before 26.6.1
- Apple iPadOS before 18.7.10 and before 26.6.1
- Apple macOS Tahoe before 26.6.2
- Apple tvOS before 27
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-08-17: disclosed: Published in Apple security advisory
- 2026-08-17: patched: Fixed in Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27