Junglewise Threat Intelligence

CVE-2026-65332: Apple Safari WebKit state management DoS vulnerability

CVE-2026-65332 · Severity: medium · CVSS 4.3 · Published 2026-08-17

Technologies: Apple Safari, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Safari is Apple's web browser used by millions of users to browse the internet. A flaw in Safari's internal state management can be triggered by visiting a malicious website, causing the browser to unexpectedly crash and interrupt the user's work. While not providing attackers access to data or system control, the crash could be used as a disruption tactic or as part of a broader attack chain.

Technical details

CVE-2026-65332 is an out-of-bounds access vulnerability in WebKit, the rendering engine powering Safari. The issue stems from improper state management when processing maliciously crafted web content, leading to a memory safety violation. The vulnerability is reachable over the network through a standard web browser request—no authentication or special user interaction beyond visiting the malicious site is required. A successful exploit causes Safari to crash unexpectedly. Apple patched this issue in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2 via improved bounds checking and state management.

Affected products

  • Apple Safari before 26.6.1
  • Apple iOS before 26.6.1
  • Apple iPadOS before 26.6.1
  • Apple macOS Tahoe before 26.6.2

Timeline

  • 2026-08-17: disclosed
  • 2026-08-17: patched

References

Related threats