ZeroHour

CVE-2026-65390

mass

Integer Overflow in Apple WebKit/Safari Allows Memory Corruption from Malicious Web Content

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-65390 is an integer overflow (CWE-190) in Apple's WebKit browser engine that was fixed with improved input validation. The flaw is triggered when a victim processes maliciously crafted web content — for example, visiting an attacker-controlled or compromised website — which can lead to memory corruption and potential arbitrary code execution within the browser context, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8; network vector, no privileges required, but user interaction required). Affected products span Apple's entire device lineup: Safari on macOS, plus iPhone, iPad, Mac (Tahoe), Apple TV, Apple Watch, and Apple Vision Pro. Notably, on iOS and iPadOS all third-party browsers (Chrome, Firefox, etc.) also use WebKit, so any browser on an unpatched Apple device is exposed. There is currently no evidence of exploitation in the wild, no public proof of concept, and the CVE is not in CISA's Known Exploited Vulnerabilities catalog.

What to do: Update all Apple devices promptly: Safari 26.6.1 and macOS Tahoe 26.6.2 on Macs, iOS/iPadOS 26.6.1 on iPhones and iPads, and tvOS/visionOS/watchOS 27 on Apple TV, Vision Pro, and Apple Watch. On iOS/iPadOS, remember the OS update also patches WebKit for every third-party browser, so a Safari-only workaround is insufficient. Because exploitation requires the user to load malicious web content, block known-malicious links in mail/web filters where possible and verify patch compliance via MDM or Software Update status.

Affected
Apple Safari (macOS)prior to 26.6.1
Apple iOSprior to 26.6.1
Apple iPadOSprior to 26.6.1
Apple macOS Tahoeprior to 26.6.2
Apple tvOSprior to 27
Apple visionOSprior to 27
Apple watchOSprior to 27
Estimated exposure
mass≈1-2 billion devices (order of magnitude), given WebKit ships on effectively all Apple hardware — Apple reports well over 2 billion active devices worldwide, and Safari/WebKit is the preinstalled default browser and mandatory engine for all iOS/iPadOS browsers, so any device not yet patched is plausibly exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.

Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.