CVE-2026-65390

Apple · Safari, iOS, iPadOS, macOS, tvOS, visionOS, watchOS

An integer overflow vulnerability in multiple Apple platforms allows for memory corruption when processing maliciously crafted web content.

Executive summary

A critical memory corruption vulnerability affecting the Apple ecosystem allows unauthenticated attackers to trigger integer overflows via malicious web content.

Vulnerability

This is an integer overflow flaw resulting from improper input validation. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to process maliciously crafted web content, leading to memory corruption.

Business impact

Successful exploitation of this memory corruption vulnerability can lead to unauthorized code execution or system instability. Given the CVSS score of 8.8, this poses a significant risk to organizational data integrity and device security. Compromised devices may be leveraged as entry points for further lateral movement within the corporate network.

Remediation

Immediate Action: Update all affected Apple devices to the specified fixed versions: Safari 26.6.1, iOS/iPadOS 26.6.1, macOS 26.6.2, or tvOS/visionOS/watchOS 27.

Proactive Monitoring: Monitor device logs for unusual browser crashes or unexpected process termination patterns that may indicate failed exploitation attempts.

Compensating Controls: Ensure that content filtering solutions and secure web gateways are active to block access to known malicious domains or suspicious web content.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the high severity of this memory corruption flaw and its broad impact across the Apple product line, immediate patching is required. Administrators should prioritize the deployment of these updates to all managed endpoints to prevent potential remote code execution scenarios.

More Apple CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written

Sources