HIGH
CVE-2026-64783
CVSS
8.8
Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Summary dbcve.org
Use-after-free vulnerability in WebKit affecting Safari and system browsers on iOS, iPadOS, macOS, visionOS, and watchOS. Processing maliciously crafted web content can trigger the vulnerability, leading to unexpected browser crashes.
Mitigation
Apply vendor security updates to Safari 26.6, iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, or watchOS 26.6 as appropriate for affected devices.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
0.43%
Probability of exploitation in next 30 days
36.7th percentile
References
https://support.apple.com/en-us/128066
Release Notes, Vendor Advisory
https://support.apple.com/en-us/128067
Release Notes, Vendor Advisory
https://support.apple.com/en-us/128068
Release Notes, Vendor Advisory
https://support.apple.com/en-us/128070
Release Notes, Vendor Advisory
https://support.apple.com/en-us/128073
Release Notes, Vendor Advisory
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.