Unrated severityNVD Advisory· Published Mar 25, 2026· Updated Apr 2, 2026
CVE-2026-20664
CVE-2026-20664
Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.
Affected products
9- Range: <26.4
<26.4+ 1 more
- (no CPE)range: <26.4
- (no CPE)range: 0
<26.4+ 1 more
- (no CPE)range: <26.4
- (no CPE)range: 0
- Range: <26.4
- Range: <26.4
- Range: 0
- Apple/iOS and iPadOSv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
9- Apple Patches Everything, (Mon, May 11th)SANS Internet Storm Center · May 11, 2026
- Attackers Actively Exploiting Critical Vulnerability in Breeze Cache PluginWordfence Blog · May 5, 2026
- CloudZ RAT potentially steals OTP messages using Pheno pluginCisco Talos Intelligence · May 5, 2026
- Today's Odd Web Requests, (Wed, Apr 29th)SANS Internet Storm Center · Apr 29, 2026
- HTTP Requests with X-Vercel-Set-Bypass-Cookie Header, (Tue, Apr 28th)SANS Internet Storm Center · Apr 28, 2026
- Attackers Actively Exploiting Critical Vulnerability in Ninja Forms – File Upload PluginWordfence Blog · Apr 16, 2026
- 30th March – Threat Intelligence ReportCheck Point Research · Mar 30, 2026
- Risky Business #830 -- LiteLLM and security scanner supply chains compromisedRisky Business · Mar 25, 2026
- Siemens SIMATICCISA Alerts