SB2026081771 - Multiple vulnerabilities in Apple Safari



SB2026081771 - Multiple vulnerabilities in Apple Safari

Published: August 17, 2026 Updated: August 17, 2026

Security Bulletin ID SB2026081771
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 10
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 60% Low 40%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 10 vulnerabilities.


1) Incorrect authorization (CVE-ID: CVE-2026-43792)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive user data.

The vulnerability exists due to improper authorization in Safari when handling app access to user data. A local user can access sensitive user data to disclose sensitive user data.


2) Information disclosure (CVE-ID: CVE-2026-64713)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to determine whether the user has visited a given link.

The vulnerability exists due to insufficient checks in WebKit when rendering web content. A remote attacker can host malicious web content to determine whether the user has visited a given link.


3) Spoofing attack (CVE-ID: CVE-2026-64730)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform ui spoofing.

The vulnerability exists due to improper UI handling in WebKit when visiting a website that frames malicious content. A remote attacker can frame malicious content to perform ui spoofing.

User interaction is required to visit a website that frames malicious content.


4) Improper access control (CVE-ID: CVE-2026-64728)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to violate iframe sandboxing policy.

The vulnerability exists due to improper access control in WebKit when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to violate iframe sandboxing policy.


5) Use-after-free (CVE-ID: CVE-2026-64783)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in WebKit when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to cause a denial of service.

User interaction is required to process the crafted web content.


6) Buffer overflow (CVE-ID: CVE-2026-64757)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to memory corruption in WebKit when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to cause a denial of service.

User interaction is required to process the crafted web content.


7) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-43804)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper state management in WebKit when visiting a website. A remote attacker can host a crafted website to cause a denial of service.

User interaction is required to visit the website.


8) Improper access control (CVE-ID: CVE-2026-43821)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read files outside of its sandbox.

The vulnerability exists due to improper access control in WebKit when an app accesses sandbox-restricted files. A local user can read files outside of its sandbox to read files outside of its sandbox.


9) Use-after-free (CVE-ID: CVE-2026-64718)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in WebKit Canvas when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to cause a denial of service.

User interaction is required to process the crafted web content.


10) Out-of-bounds write (CVE-ID: CVE-2026-64719)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds access in WebRTC when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to cause a denial of service.

User interaction is required to process the crafted web content.


Remediation

Install update from vendor's website.