ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-610: Apple Safari JavaScriptCore B3 ReduceStrength Phase Use-After-Free Remote Code Execution Vulnerability

AI summary · glm-5.3-flash

ZDI details a use-after-free in Apple Safari's JavaScriptCore (CVE-2026-64715) that allows remote code execution after a user visits a malicious page.

The Zero Day Initiative published advisory ZDI-26-610 for a use-after-free in the B3 ReduceStrength phase of Apple Safari's JavaScriptCore. Successful exploitation allows remote attackers to execute arbitrary code, but user interaction is required, such as visiting a malicious page or opening a malicious file. ZDI rates the vulnerability 8.8 on CVSS and assigned CVE-2026-64715. The advisory does not report exploitation in the wild.

  • Use-after-free in JavaScriptCore B3 ReduceStrength phase enables remote code execution
  • Requires user interaction such as visiting an attacker-controlled page
  • CVSS 8.8; tracked as CVE-2026-64715 under ZDI-26-610

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-64715
Use-After-Free in Apple Safari and iOS/iPadOS/macOS Web Content Processing

CVE-2026-64715 is a use-after-free (CWE-416) memory-safety flaw in Apple's web content processing stack, addressed with improved memory management in Safari 26.6.1, iOS/iPadOS 18.7.10 and 26.6.1, and macOS Tahoe 26.6.2. It is triggered when a user processes maliciously crafted web content — typically by visiting an attacker-controlled webpage in Safari or another WebKit-based view. Per Apple's advisory, a successful trigger leads to an unexpected process crash (denial of service), reflected in the CVSS score of 6.5 with availability-only impact, though the related Zero Day Initiative advisory (ZDI-26-610) characterizes the JavaScriptCore B3 ReduceStrength use-after-free as potentially leading to remote code execution. All users of the affected Safari, iOS, iPadOS, and macOS versions on Apple hardware are exposed until they apply the updates. There is currently no known exploitation in the wild, no public proof-of-concept, no CISA KEV listing, and a low EPSS score (0.4% probability of exploitation in 30 days).

Do: Update Safari to 26.6.1, iOS/iPadOS to 18.7.10 (older-branch devices) or 26.6.1 (current branch), and macOS Tahoe to 26.6.2. In the interim, avoid untrusted websites and ensure WebKit-based in-app browsers are patched via OS updates. Inventory Apple fleets for these versions and prioritize updates, monitoring for public PoCs given ZDI's characterization of the bug as potentially leading to remote code execution.

6.5<1%
  • apple Safari versions prior to 26.6.1
  • apple iPhone OS (iOS) versions prior to 18.7.10 and versions prior to 26.6.1 (both supported update branches)
  • apple iPadOS versions prior to 18.7.10 and versions prior to 26.6.1 (both supported update branches)
  • +1 more
mass≈1 billion+ users/devices (Safari and iOS/iPadOS active install base)
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-64715.

This source does not provide full text. Read it at zerodayinitiative.com.