Executive brief
Safari is Apple's web browser used by millions of users on iOS, iPadOS, and macOS. A maliciously crafted web page can trigger a memory handling flaw in Safari's WebKit rendering engine, causing the browser to crash unexpectedly. While not a direct data breach, repeated crashes degrade user experience and interrupt work, and could be exploited alongside other attacks.
Technical details
CVE-2026-65338 is a memory handling vulnerability in Apple's WebKit engine affecting Safari across multiple platforms. The flaw is triggered when Safari processes maliciously crafted web content, leading to an unexpected crash (denial of service). The vulnerability was addressed through improved memory handling in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27. The attack vector is network-based and requires only that a user visit or view malicious content in Safari; no authentication or special privilege is required. Apple has not publicly disclosed evidence of in-the-wild exploitation as of the advisory date.
Affected products
- Apple Safari before 26.6.1
- Apple iOS before 26.6.1
- Apple iPadOS before 26.6.1
- Apple macOS Tahoe before 26.6.2
- Apple visionOS before 27
Timeline
- 2026-08-17: disclosed: CVE-2026-65338 published and patches released