Junglewise Threat Intelligence

CVE-2026-65338: Apple Safari WebKit memory handling denial of service

CVE-2026-65338 · Severity: medium · CVSS 4.3 · Published 2026-08-17

Technologies: Apple Safari, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Safari is Apple's web browser used by millions of users on iOS, iPadOS, and macOS. A maliciously crafted web page can trigger a memory handling flaw in Safari's WebKit rendering engine, causing the browser to crash unexpectedly. While not a direct data breach, repeated crashes degrade user experience and interrupt work, and could be exploited alongside other attacks.

Technical details

CVE-2026-65338 is a memory handling vulnerability in Apple's WebKit engine affecting Safari across multiple platforms. The flaw is triggered when Safari processes maliciously crafted web content, leading to an unexpected crash (denial of service). The vulnerability was addressed through improved memory handling in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27. The attack vector is network-based and requires only that a user visit or view malicious content in Safari; no authentication or special privilege is required. Apple has not publicly disclosed evidence of in-the-wild exploitation as of the advisory date.

Affected products

  • Apple Safari before 26.6.1
  • Apple iOS before 26.6.1
  • Apple iPadOS before 26.6.1
  • Apple macOS Tahoe before 26.6.2
  • Apple visionOS before 27

Timeline

  • 2026-08-17: disclosed: CVE-2026-65338 published and patches released

References

Related threats