Executive brief
Safari is Apple's web browser used by millions to browse the internet. A memory safety flaw in Safari's web rendering engine (WebKit) can cause the browser to unexpectedly crash when processing malicious web content, potentially disrupting user workflow and creating a denial-of-service condition for affected devices.
Technical details
CVE-2026-65333 is an out-of-bounds access vulnerability in Apple's WebKit engine, the rendering component shared across Safari, iOS, and iPadOS browsers. The vulnerability is triggered by processing maliciously crafted web content and results in an unexpected Safari crash (denial of service). The issue was fixed through improved bounds checking on memory access operations. Attack vector is network-based; an attacker can serve malicious web content to trigger the crash with no user interaction beyond normal browsing. Patches are available in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27 (all released August 17, 2026).
Affected products
- Apple Safari before 26.6.1
- Apple iOS before 26.6.1
- Apple iPadOS before 26.6.1
- Apple macOS Tahoe before 26.6.2
- Apple visionOS before 27
Timeline
- 2026-08-17: disclosed: CVE-2026-65333 published; patches released
- 2026-08-17: patched: Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27