CVE-2026-65391
massOut-of-Bounds Write in Apple Safari/WebKit Web Content Rendering
CVE-2026-65391 is an out-of-bounds write (CWE-190, integer overflow/wraparound) in Apple's web content processing engine, fixed with improved bounds checking. It is triggered when a victim simply visits a maliciously crafted web page in Safari or any WebKit-based view, requiring no privileges but some user interaction (CVSS 3.1: 8.8). Successful exploitation causes memory corruption, plausibly yielding arbitrary code execution within the browser/renderer context with high impact on confidentiality, integrity, and availability. Affected software includes Safari and the WebKit engine bundled with iOS/iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS, all patched in the versions listed below. There is no known public proof-of-concept, no confirmed in-the-wild exploitation, and the flaw is not on the CISA KEV list.
What to do: Patch immediately: update macOS Tahoe to 26.6.2 (or Safari to 26.6.1), iOS/iPadOS to 26.6.1, and tvOS, visionOS, and watchOS to 27. Enable automatic software updates on all Apple devices, and use MDM to force patch rollout in managed fleets. Because the attack vector is malicious web content, users on unpatched devices should avoid browsing untrusted sites until updated; defenders should watch for post-patch anomaly reports and Apple's security advisory for any exploitation addendum.
| Apple Safari (macOS) | versions prior to 26.6.1 |
| Apple iOS | versions prior to 26.6.1 |
| Apple iPadOS | versions prior to 26.6.1 |
| Apple macOS Tahoe | versions prior to 26.6.2 |
| Apple tvOS | versions prior to 27 |
| Apple visionOS | versions prior to 27 |
| Apple watchOS | versions prior to 27 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.