Junglewise Threat Intelligence

CVE-2026-65336: Apple Safari WebKit out-of-bounds access in state management

CVE-2026-65336 · Severity: medium · CVSS 4.3 · Published 2026-08-17

Technologies: Apple macOS, Apple Safari, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Safari is Apple's web browser used by millions of users on Mac, iPhone, and iPad to access the internet. A flaw in Safari's web rendering engine (WebKit) can cause the browser to unexpectedly crash when processing specially crafted malicious web content, disrupting user productivity and potentially serving as a stepping stone for further attacks.

Technical details

CVE-2026-65336 is an out-of-bounds access vulnerability in WebKit, Safari's rendering engine, that occurs during state management of web content. The vulnerability is triggered by processing maliciously crafted web content, which can lead to an unexpected Safari crash. The issue was addressed through improved bounds checking. The vulnerability affects Safari 26.6.1 and earlier, iOS 18.7.10 and earlier, iPadOS 18.7.10 and earlier, and macOS Tahoe 26.6.2 and earlier. No authentication is required; the attack vector is network-based and requires only that a user visit or be directed to a malicious website.

Affected products

  • Apple Safari before 26.6.1
  • Apple iOS before 26.6.1
  • Apple iPadOS before 26.6.1
  • Apple macOS Tahoe before 26.6.2
  • Apple visionOS before 27

Timeline

  • 2026-08-17: disclosed: CVE-2026-65336 published
  • 2026-08-17: patched: Fix released in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27

References

Related threats