CVE-2026-65390
massInteger Overflow in Apple WebKit/Safari Allows Memory Corruption from Malicious Web Content
CVE-2026-65390 is an integer overflow (CWE-190) in Apple's WebKit browser engine that was fixed with improved input validation. The flaw is triggered when a victim processes maliciously crafted web content — for example, visiting an attacker-controlled or compromised website — which can lead to memory corruption and potential arbitrary code execution within the browser context, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8; network vector, no privileges required, but user interaction required). Affected products span Apple's entire device lineup: Safari on macOS, plus iPhone, iPad, Mac (Tahoe), Apple TV, Apple Watch, and Apple Vision Pro. Notably, on iOS and iPadOS all third-party browsers (Chrome, Firefox, etc.) also use WebKit, so any browser on an unpatched Apple device is exposed. There is currently no evidence of exploitation in the wild, no public proof of concept, and the CVE is not in CISA's Known Exploited Vulnerabilities catalog.
What to do: Update all Apple devices promptly: Safari 26.6.1 and macOS Tahoe 26.6.2 on Macs, iOS/iPadOS 26.6.1 on iPhones and iPads, and tvOS/visionOS/watchOS 27 on Apple TV, Vision Pro, and Apple Watch. On iOS/iPadOS, remember the OS update also patches WebKit for every third-party browser, so a Safari-only workaround is insufficient. Because exploitation requires the user to load malicious web content, block known-malicious links in mail/web filters where possible and verify patch compliance via MDM or Software Update status.
| Apple Safari (macOS) | prior to 26.6.1 |
| Apple iOS | prior to 26.6.1 |
| Apple iPadOS | prior to 26.6.1 |
| Apple macOS Tahoe | prior to 26.6.2 |
| Apple tvOS | prior to 27 |
| Apple visionOS | prior to 27 |
| Apple watchOS | prior to 27 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.