ZeroHour

CVE-2026-65391

mass

Out-of-Bounds Write in Apple Safari/WebKit Web Content Rendering

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-65391 is an out-of-bounds write (CWE-190, integer overflow/wraparound) in Apple's web content processing engine, fixed with improved bounds checking. It is triggered when a victim simply visits a maliciously crafted web page in Safari or any WebKit-based view, requiring no privileges but some user interaction (CVSS 3.1: 8.8). Successful exploitation causes memory corruption, plausibly yielding arbitrary code execution within the browser/renderer context with high impact on confidentiality, integrity, and availability. Affected software includes Safari and the WebKit engine bundled with iOS/iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS, all patched in the versions listed below. There is no known public proof-of-concept, no confirmed in-the-wild exploitation, and the flaw is not on the CISA KEV list.

What to do: Patch immediately: update macOS Tahoe to 26.6.2 (or Safari to 26.6.1), iOS/iPadOS to 26.6.1, and tvOS, visionOS, and watchOS to 27. Enable automatic software updates on all Apple devices, and use MDM to force patch rollout in managed fleets. Because the attack vector is malicious web content, users on unpatched devices should avoid browsing untrusted sites until updated; defenders should watch for post-patch anomaly reports and Apple's security advisory for any exploitation addendum.

Affected
Apple Safari (macOS)versions prior to 26.6.1
Apple iOSversions prior to 26.6.1
Apple iPadOSversions prior to 26.6.1
Apple macOS Tahoeversions prior to 26.6.2
Apple tvOSversions prior to 27
Apple visionOSversions prior to 27
Apple watchOSversions prior to 27
Estimated exposure
mass≈1 billion+ devices (Safari/WebKit ships by default on essentially all iPhones, iPads, and Macs, plus Apple TV, Watch, and Vision Pro) — Apple has publicly reported well over 2 billion active devices worldwide, and Safari/WebKit is the default rendering engine on every one of them, so any device not yet running the patched OS or Safari versions is potentially exposed to a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.

Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.