Junglewise Threat Intelligence

CVE-2026-65331: Apple Safari WebKit state management vulnerability

CVE-2026-65331 · Severity: medium · CVSS 4.3 · Published 2026-08-17

Technologies: Apple Safari, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Safari is Apple's web browser used by millions to access websites. A flaw in its web content processing engine (WebKit) can cause Safari to crash unexpectedly when a user visits a malicious website. While this does not directly expose data or allow code execution, it disrupts user productivity and could be chained with other attacks to achieve more serious outcomes.

Technical details

CVE-2026-65331 is an out-of-bounds access or state management flaw in WebKit, Apple's browser rendering engine. The vulnerability is triggered when processing maliciously crafted web content, leading to an unexpected Safari crash (denial of service). The issue was addressed through improved state management and bounds checking. The vulnerability affects Safari 26.6.1 and earlier, iOS 26.6.1 and earlier, iPadOS 26.6.1 and earlier, and macOS Tahoe 26.6.2 and earlier. No authentication or special privileges are required; simply visiting a malicious website over the network is sufficient to trigger the crash. Patches are available in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2.

Affected products

  • Apple Safari before 26.6.1
  • Apple iOS before 26.6.1
  • Apple iPadOS before 26.6.1
  • Apple macOS Tahoe before 26.6.2

Timeline

  • 2026-08-17: disclosed: CVE-2026-65331 published and patches released

References

Related threats