CVE-2026-65351
published 2026-08-17CVE-2026-65351: This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing…
PriorityP420medium4.3CVSS 3.1
AVNACLPRNUIRSUCNINAL
EPSS
0.46%
38.5th percentile
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 26.6.1 | 26.6.1 |
| apple | ipados | < 26.6.1 | 26.6.1 |
| apple | iphone_os | < 26.6.1 | 26.6.1 |
| apple | macos | < 26.6.2 | 26.6.2 |
| apple | macos | >= 26.0 < 26.6.2 | 26.6.2 |
| apple | safari | < 26.6.1 | 26.6.1 |
| webkitgtk | webkitgtk | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple iOS/iPadOS/macOS prior 26.6.1/26.6.2 denial of service
vuldb·2026-08-18
CVE-2026-65351 [CRITICAL] Apple iOS/iPadOS/macOS prior 26.6.1/26.6.2 denial of service
A vulnerability has been found in Apple iOS, iPadOS and macOS and classified as critical. This impacts an unknown function. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2026-65351. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
GHSA
This issue was addressed through improved state management.
ghsa_unreviewed·2026-08-18
CVE-2026-65351 [MEDIUM] CWE-703 This issue was addressed through improved state management.
This issue was addressed through improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Red Hat
webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
vendor_redhat·2026-08-17·CVSS 4.3
CVE-2026-65351 [MEDIUM] CWE-120 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper state management.
Statement: To exploit this issue, an attacker needs to trick a user into processing or loading malicious web content. For this reason, this flaw has been rated with an important severity.
Additionally, this issue can cause an unexpected process crash but the possibility of remote code execution is not discarded.
Mitigation: Do not pro
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-65351 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [fedora-all]
bugzilla·2026-08-27·CVSS 4.3
CVE-2026-65351 [MEDIUM] CVE-2026-65351 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [fedora-all]
CVE-2026-65351 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Bugzilla
CVE-2026-65351 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [epel-all]
bugzilla·2026-08-27·CVSS 4.3
CVE-2026-65351 [MEDIUM] CVE-2026-65351 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [epel-all]
CVE-2026-65351 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Bugzilla
CVE-2026-65351 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
bugzilla·2026-08-26·CVSS 4.3
CVE-2026-65351 [MEDIUM] CVE-2026-65351 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVE-2026-65351 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
2026-08-17
Published