Executive brief
Safari is Apple's web browser used by millions of users on Mac, iPhone, and iPad to access the internet. A flaw in Safari's web rendering engine (WebKit) can cause the browser to unexpectedly crash when processing specially crafted malicious web content, disrupting user productivity and potentially serving as a stepping stone for further attacks.
Technical details
CVE-2026-65336 is an out-of-bounds access vulnerability in WebKit, Safari's rendering engine, that occurs during state management of web content. The vulnerability is triggered by processing maliciously crafted web content, which can lead to an unexpected Safari crash. The issue was addressed through improved bounds checking. The vulnerability affects Safari 26.6.1 and earlier, iOS 18.7.10 and earlier, iPadOS 18.7.10 and earlier, and macOS Tahoe 26.6.2 and earlier. No authentication is required; the attack vector is network-based and requires only that a user visit or be directed to a malicious website.
Affected products
- Apple Safari before 26.6.1
- Apple iOS before 26.6.1
- Apple iPadOS before 26.6.1
- Apple macOS Tahoe before 26.6.2
- Apple visionOS before 27
Timeline
- 2026-08-17: disclosed: CVE-2026-65336 published
- 2026-08-17: patched: Fix released in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27