Executive brief
Safari's web rendering engine (WebKit) contains a flaw in how it manages internal state when processing web content. A malicious website can exploit this to crash Safari unexpectedly, disrupting user browsing and potentially causing data loss if unsaved work is in progress. The issue affects Safari, iOS, iPadOS, macOS, and visionOS across multiple versions.
Technical details
CVE-2026-65337 is a state management vulnerability in Apple WebKit, the rendering engine used by Safari and iOS/iPadOS browsers. The vulnerability is triggered by processing maliciously crafted web content, leading to an unexpected Safari process crash. The root cause was addressed through improved state management in the WebKit codebase (WebKit Bugzilla #317142). The attack vector is network-based and requires no user authentication beyond visiting a malicious website. An attacker can achieve a denial-of-service condition by crashing the Safari browser. The vulnerability has been patched in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27.
Affected products
- Apple Safari before 26.6.1
- Apple iOS before 26.6.1
- Apple iPadOS before 26.6.1
- Apple macOS Tahoe before 26.6.2
- Apple visionOS before 27
Timeline
- 2026-08-17: disclosed: CVE-2026-65337 published and patches released
- 2026-08-17: patched: Patches available in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27