Executive brief
Safari and iOS/iPadOS browsers include a memory management flaw that can cause unexpected crashes when processing malicious web content. An attacker can exploit this by hosting a specially crafted website that, when visited, crashes Safari or the device's browser—disrupting user access to web services and potentially eroding customer trust in Apple's browser stability.
Technical details
A memory corruption vulnerability in WebKit's state management was addressed through improved state management mechanisms. The issue occurs when processing maliciously crafted web content, which can trigger unexpected memory access patterns leading to Safari crashes. The attack vector is network-based: a user must visit a malicious website in Safari, with no authentication required. The impact is primarily denial of service (application crash); the advisory does not indicate arbitrary code execution risk. Patches are available in Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, macOS Tahoe 26.6.2, and visionOS 27.
Affected products
- Apple Safari before 26.6.1
- Apple iOS before 18.7.10
- Apple iPadOS before 18.7.10
- Apple macOS Tahoe before 26.6.2
- Apple visionOS before 27
Timeline
- 2026-08-17: disclosed
- 2026-08-17: patched