Executive brief
Safari is Apple's web browser used by millions of users to browse the internet. A memory corruption vulnerability in Safari's rendering engine could allow attackers to crash the browser or potentially execute malicious code when users view specially crafted websites. This poses a risk to user data and system stability.
Technical details
An out-of-bounds write vulnerability exists in Safari's memory handling, triggered when processing maliciously crafted web content. The vulnerability stems from insufficient bounds checking in memory operations, allowing an attacker to write data beyond allocated buffer boundaries. The attack vector is network-based, requiring a user to visit a malicious webpage—no authentication or additional privileges required. Successful exploitation can lead to memory corruption, crashes, or potentially arbitrary code execution. The issue is fixed in Safari 26.6.1 and subsequent versions (iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27) with improved bounds checking.
Affected products
- Apple Safari before 26.6.1
- Apple iOS before 26.6.1
- Apple iPadOS before 26.6.1
- Apple macOS Tahoe before 26.6.2
- Apple tvOS before 27
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: disclosed: CVE-2026-65391 published
- 2026-08-17: patched: Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27 released