Junglewise Threat Intelligence

CVE-2026-65391: Apple Safari out-of-bounds write in memory handling

CVE-2026-65391 · Severity: high · CVSS 8.8 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS, Apple Safari, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Safari is Apple's web browser used by millions of users to browse the internet. A memory corruption vulnerability in Safari's rendering engine could allow attackers to crash the browser or potentially execute malicious code when users view specially crafted websites. This poses a risk to user data and system stability.

Technical details

An out-of-bounds write vulnerability exists in Safari's memory handling, triggered when processing maliciously crafted web content. The vulnerability stems from insufficient bounds checking in memory operations, allowing an attacker to write data beyond allocated buffer boundaries. The attack vector is network-based, requiring a user to visit a malicious webpage—no authentication or additional privileges required. Successful exploitation can lead to memory corruption, crashes, or potentially arbitrary code execution. The issue is fixed in Safari 26.6.1 and subsequent versions (iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27) with improved bounds checking.

Affected products

  • Apple Safari before 26.6.1
  • Apple iOS before 26.6.1
  • Apple iPadOS before 26.6.1
  • Apple macOS Tahoe before 26.6.2
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-65391 published
  • 2026-08-17: patched: Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27 released

References

Related threats