Junglewise Threat Intelligence

CVE-2026-65335: Apple Safari WebKit out-of-bounds access in state management

CVE-2026-65335 · Severity: medium · CVSS 4.3 · Published 2026-08-17

Technologies: Apple Safari, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Safari is Apple's web browser used by millions of users on iPhones, iPads, and Macs. A defect in Safari's web content processing can cause the browser to crash unexpectedly when viewing a maliciously crafted website. While the immediate impact is limited to a browser crash rather than data theft or system compromise, repeated crashes degrade user experience and may be used as part of a larger attack chain.

Technical details

CVE-2026-65335 is an out-of-bounds access vulnerability in WebKit's state management logic, triggered when processing maliciously crafted web content. The issue resides in the WebKit rendering engine and is reachable over the network simply by visiting a malicious website—no authentication or user interaction beyond normal browsing is required. Successful exploitation leads to an unexpected Safari process crash (denial of service). Apple addressed the vulnerability through improved bounds checking and is released in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2 as of August 17, 2026.

Affected products

  • Apple Safari before 26.6.1
  • Apple iOS before 26.6.1
  • Apple iPadOS before 26.6.1
  • Apple macOS Tahoe before 26.6.2

Timeline

  • 2026-08-17: disclosed
  • 2026-08-17: patched: Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2

References

Related threats