Junglewise Threat Intelligence

CVE-2026-65340: Apple Safari WebKit state management memory corruption

CVE-2026-65340 · Severity: medium · CVSS 4.3 · Published 2026-08-17

Technologies: Apple Safari, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Safari's web rendering engine (WebKit) contains a flaw in its state management that can cause the browser to crash when processing malicious web pages. An attacker can craft a specially designed website that, when visited, triggers an unexpected Safari crash, disrupting user browsing and potentially exposing the browser to further exploitation.

Technical details

The vulnerability is a state management issue in Apple's WebKit engine that leads to out-of-bounds memory access. The flaw is triggered when processing maliciously crafted web content, resulting in an unexpected Safari crash. The attack vector is network-based—a user must visit a malicious website—with no authentication or special privileges required. The fix involves improved bounds checking and state validation in WebKit's memory handling code, deployed in Safari 26.6.1, macOS Tahoe 26.6.2, iOS 26.6.1, and iPadOS 26.6.1.

Affected products

  • Apple Safari before 26.6.1
  • Apple iOS before 26.6.1
  • Apple iPadOS before 26.6.1
  • Apple macOS Tahoe before 26.6.2

Timeline

  • 2026-08-17: disclosed
  • 2026-08-17: patched

References

Related threats