Executive brief
WebKit is the rendering engine that powers Safari and iOS web browsing on Apple devices. A memory corruption vulnerability in WebKit can be triggered by processing maliciously crafted web content, potentially leading to Safari crashes or system instability. An attacker could exploit this by hosting malicious web pages that users visit, impacting system reliability and user experience.
Technical details
CVE-2026-65341 is a memory corruption vulnerability in Apple's WebKit engine caused by a logic error in memory handling. The vulnerability is triggered when processing maliciously crafted web content delivered over the network. The attack vector requires user interaction (visiting a malicious website) but no authentication. An attacker can achieve a denial of service by crashing the Safari browser or potentially corrupt memory to achieve further exploitation. The vulnerability is fixed in Safari 26.6.1, iOS/iPadOS 26.6.1, macOS Tahoe 26.6.2, and later versions through improved memory handling.
Affected products
- Apple Safari before 26.6.1
- Apple iOS before 26.6.1
- Apple iPadOS before 26.6.1
- Apple macOS Tahoe before 26.6.2
- Apple tvOS before 27
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-08-17: disclosed: CVE-2026-65341 published alongside security updates
- 2026-08-17: patched: Patches released for Safari 26.6.1, iOS/iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27