CVE-2026-65391
Apple · Safari, iOS, iPadOS, macOS, tvOS, visionOS, watchOS
An out-of-bounds write vulnerability in multiple Apple platforms allows for memory corruption when processing maliciously crafted web content.
Executive summary
A critical out-of-bounds write vulnerability in Apple software could allow a remote attacker to achieve memory corruption via malicious web content.
Vulnerability
This vulnerability is an out-of-bounds write flaw caused by insufficient bounds checking. An unauthenticated remote attacker can trigger this memory corruption by enticing a user to process maliciously crafted web content.
Business impact
Successful exploitation of this vulnerability can result in full memory corruption, potentially leading to arbitrary code execution or a complete system crash. With a CVSS score of 8.8, this flaw represents a significant risk to organizational integrity and data confidentiality, as it enables attackers to compromise endpoint security via standard web browsing activities.
Remediation
Immediate Action: Update all affected Apple devices to the following versions: Safari 26.6.1, iOS/iPadOS 26.6.1, macOS 26.6.2, and tvOS/visionOS/watchOS 27.
Proactive Monitoring: Review web proxy and endpoint logs for abnormal traffic patterns or unexpected crashes associated with browser processes.
Compensating Controls: Ensure that endpoint protection software is active and configured to block known malicious domains, which may reduce the likelihood of a user being directed to the web content required to trigger this flaw.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the severity of this memory corruption vulnerability and the widespread use of Apple products, immediate patching is required. Organizations should prioritize deploying these updates across all managed mobile and desktop environments to eliminate the risk of remote exploitation.
More Apple CVEs all →
History
CVE Brief tracked this CVE 3 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written