CVE-2026-65391

Apple · Safari, iOS, iPadOS, macOS, tvOS, visionOS, watchOS

An out-of-bounds write vulnerability in multiple Apple platforms allows for memory corruption when processing maliciously crafted web content.

Executive summary

A critical out-of-bounds write vulnerability in Apple software could allow a remote attacker to achieve memory corruption via malicious web content.

Vulnerability

This vulnerability is an out-of-bounds write flaw caused by insufficient bounds checking. An unauthenticated remote attacker can trigger this memory corruption by enticing a user to process maliciously crafted web content.

Business impact

Successful exploitation of this vulnerability can result in full memory corruption, potentially leading to arbitrary code execution or a complete system crash. With a CVSS score of 8.8, this flaw represents a significant risk to organizational integrity and data confidentiality, as it enables attackers to compromise endpoint security via standard web browsing activities.

Remediation

Immediate Action: Update all affected Apple devices to the following versions: Safari 26.6.1, iOS/iPadOS 26.6.1, macOS 26.6.2, and tvOS/visionOS/watchOS 27.

Proactive Monitoring: Review web proxy and endpoint logs for abnormal traffic patterns or unexpected crashes associated with browser processes.

Compensating Controls: Ensure that endpoint protection software is active and configured to block known malicious domains, which may reduce the likelihood of a user being directed to the web content required to trigger this flaw.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the severity of this memory corruption vulnerability and the widespread use of Apple products, immediate patching is required. Organizations should prioritize deploying these updates across all managed mobile and desktop environments to eliminate the risk of remote exploitation.

More Apple CVEs all →

History

CVE Brief tracked this CVE 3 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written

Sources