VYPR
patchPublished Aug 17, 2026· Updated Aug 24, 2026· 2 sources

Apple Safari: Nine WebKit Vulnerabilities Patched in Same-Day Disclosure

Key findings • Nine Safari vulnerabilities disclosed on August 17, 2026, primarily causing crashes due to memory and state management issues. • Fixes are included in iOS 26.6.1, iPadOS 26.6.1…

Key findings

  • Nine Safari vulnerabilities disclosed on August 17, 2026, primarily causing crashes due to memory and state management issues.
  • Fixes are included in iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and iOS/iPadOS 18.7.10.
  • No evidence of in-the-wild exploitation reported for this batch.
  • Vulnerabilities addressed through improved memory handling, state management, input validation, and locking.

On August 17, 2026, Apple Inc. released a significant security update addressing a batch of nine vulnerabilities impacting Safari across iOS, iPadOS, and macOS. The vulnerabilities, all disclosed on the same day, primarily relate to memory handling, state management, and input validation within the WebKit engine, which powers Safari. Processing maliciously crafted web content could lead to unexpected Safari crashes, potentially affecting system stability.

The disclosed vulnerabilities include several related to memory corruption and improved locking mechanisms, such as CVE-2026-64782 and CVE-2026-64779. Others were addressed through improved state management (CVE-2026-65351, CVE-2026-65337, CVE-2026-65333, CVE-2026-65332) or improved memory handling (CVE-2026-65338, CVE-2026-28984). CVE-2026-64781 was addressed with improved input validation. All these issues could result in an unexpected Safari crash when processing malicious web content.

According to SANS ISC, none of the disclosed vulnerabilities had been exploited in the wild prior to their patching. While this batch specifically impacts Safari, related advisories indicate that Apple patched a larger number of vulnerabilities (up to 25 in iOS and iPadOS, and 108 across iOS, iPadOS, and macOS) in the same update window.

The vulnerabilities are fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, and also in iOS 18.7.10 and iPadOS 18.7.10 for some of the issues. Users are advised to update their devices to the latest available versions to mitigate these risks.

This coordinated disclosure highlights Apple's ongoing efforts to maintain the security of its WebKit engine and Safari browser. While the immediate impact of these specific CVEs is described as Safari crashes, the broader context of a large security update suggests a comprehensive effort to address potential system stability and integrity issues across Apple's operating systems. Users should remain vigilant and apply security updates promptly.

This advisory details a specific use-after-free vulnerability within Apple Safari's JavaScriptCore B3 ReduceStrength phase, tracked as CVE-2026-64715. While the existing story covers a batch of nine WebKit vulnerabilities patched by Apple, this new information provides specific technical details on one of those flaws, highlighting its remote code execution potential via malicious webpages or files.

Synthesized by Vypr AI
Apple Safari: Nine WebKit Vulnerabilities Patched in Same-Day Disclosure · VYPR