webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
cve CVE-2026-64715 2 sources, 2 claims · Watch
Red Hat writes:
webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash the claim
webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash the claim
What it is to other things
| affects | apple/ipados NVD |
| affects | apple/iphone_os NVD |
| affects | apple/macos NVD |
| affects | apple/safari NVD |
| made_by | apple NVD |
What each source says
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Cvss cvss conflict | NVD | 6.5receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Safari",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.6.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "iOS and iPadOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "18.7.10",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "26.6.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "macOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.6.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "tvOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "27",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "visionOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "27",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "watchOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "27",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"source": "product-security@apple.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E28B5C94-2DF4-4601-B097-582626C761AA",
"versionEndExcluding": "26.6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F413C997-517E-4C4F-9506-B7295E94CFFD",
"versionEndExcluding": "18.7.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "79392FA7-F634-496F-866F-6D054133D23B",
"versionEndExcluding": "26.6.1",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "23D4A4CC-51AE-44CA-A211-5B1A7445E45B",
"versionEndExcluding": "18.7.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8C87B1B6-8A8F-4165-BC18-DE36DE5891C9",
"versionEndExcluding": "26.6.1",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ECE169FD-8BEB-45FE-82CE-FC98AD8EB3CA",
"versionEndExcluding": "26.6.2",
"versionStartIncluding": "26.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process crash."
}
],
"id": "CVE-2026-64715",
"lastModified": "2026-09-14T21:17:14.173",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-64715",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-18T13:21:36.342847Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-08-17T22:17:17.343",
"references": [
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/148281"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/148282"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/148286"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/148287"
},
{
"source": "product-security@apple.com",
"url": "https://support.apple.com/en-us/149036"
},
{
"source": "product-security@apple.com",
"url": "https://support.apple.com/en-us/149037"
},
{
"source": "product-security@apple.com",
"url": "https://support.apple.com/en-us/149038"
}
],
"sourceIdentifier": "product-security@apple.com",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-416"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| Cvss cvss conflict | Red Hat | 8.8receipt
What the source handed over{
"CVE": "CVE-2026-64715",
"CWE": "CWE-416",
"advisories": [
"RHSA-2026:69098"
],
"affected_packages": [
"webkit2gtk3-0:2.54.0-1.el9_8"
],
"bugzilla": "2524567",
"bugzilla_description": "webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash",
"cvss3_score": "8.8",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-08-17T21:29:27Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-64715.json",
"severity": "important"
} | — | ||||
| Cwe cwe | Red Hat | CWE-416receipt
What the source handed over{
"CVE": "CVE-2026-64715",
"CWE": "CWE-416",
"advisories": [
"RHSA-2026:69098"
],
"affected_packages": [
"webkit2gtk3-0:2.54.0-1.el9_8"
],
"bugzilla": "2524567",
"bugzilla_description": "webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash",
"cvss3_score": "8.8",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-08-17T21:29:27Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-64715.json",
"severity": "important"
} | — | ||||
| Packages packages | Red Hat | webkit2gtk3-0:2.54.0-1.el9_8receipt
What the source handed over{
"CVE": "CVE-2026-64715",
"CWE": "CWE-416",
"advisories": [
"RHSA-2026:69098"
],
"affected_packages": [
"webkit2gtk3-0:2.54.0-1.el9_8"
],
"bugzilla": "2524567",
"bugzilla_description": "webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash",
"cvss3_score": "8.8",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-08-17T21:29:27Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-64715.json",
"severity": "important"
} | — | ||||
| Product product | NVD | Safarireceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Safari",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.6.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "iOS and iPadOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "18.7.10",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "26.6.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "macOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.6.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "tvOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "27",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "visionOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "27",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "watchOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "27",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"source": "product-security@apple.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E28B5C94-2DF4-4601-B097-582626C761AA",
"versionEndExcluding": "26.6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F413C997-517E-4C4F-9506-B7295E94CFFD",
"versionEndExcluding": "18.7.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "79392FA7-F634-496F-866F-6D054133D23B",
"versionEndExcluding": "26.6.1",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "23D4A4CC-51AE-44CA-A211-5B1A7445E45B",
"versionEndExcluding": "18.7.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8C87B1B6-8A8F-4165-BC18-DE36DE5891C9",
"versionEndExcluding": "26.6.1",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ECE169FD-8BEB-45FE-82CE-FC98AD8EB3CA",
"versionEndExcluding": "26.6.2",
"versionStartIncluding": "26.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process crash."
}
],
"id": "CVE-2026-64715",
"lastModified": "2026-09-14T21:17:14.173",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-64715",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-18T13:21:36.342847Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-08-17T22:17:17.343",
"references": [
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/148281"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/148282"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/148286"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/148287"
},
{
"source": "product-security@apple.com",
"url": "https://support.apple.com/en-us/149036"
},
{
"source": "product-security@apple.com",
"url": "https://support.apple.com/en-us/149037"
},
{
"source": "product-security@apple.com",
"url": "https://support.apple.com/en-us/149038"
}
],
"sourceIdentifier": "product-security@apple.com",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-416"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| Severity severity | Red Hat | important A flaw that can easily compromise confidentiality, integrity or availability. receipt
What the source handed over{
"CVE": "CVE-2026-64715",
"CWE": "CWE-416",
"advisories": [
"RHSA-2026:69098"
],
"affected_packages": [
"webkit2gtk3-0:2.54.0-1.el9_8"
],
"bugzilla": "2524567",
"bugzilla_description": "webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash",
"cvss3_score": "8.8",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-08-17T21:29:27Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-64715.json",
"severity": "important"
} | high | ||||
| Status status | NVD | Modifiedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Safari",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.6.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "iOS and iPadOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "18.7.10",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "26.6.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "macOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.6.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "tvOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "27",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "visionOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "27",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "watchOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "27",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"source": "product-security@apple.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E28B5C94-2DF4-4601-B097-582626C761AA",
"versionEndExcluding": "26.6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F413C997-517E-4C4F-9506-B7295E94CFFD",
"versionEndExcluding": "18.7.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "79392FA7-F634-496F-866F-6D054133D23B",
"versionEndExcluding": "26.6.1",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "23D4A4CC-51AE-44CA-A211-5B1A7445E45B",
"versionEndExcluding": "18.7.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8C87B1B6-8A8F-4165-BC18-DE36DE5891C9",
"versionEndExcluding": "26.6.1",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ECE169FD-8BEB-45FE-82CE-FC98AD8EB3CA",
"versionEndExcluding": "26.6.2",
"versionStartIncluding": "26.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process crash."
}
],
"id": "CVE-2026-64715",
"lastModified": "2026-09-14T21:17:14.173",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-64715",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-18T13:21:36.342847Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-08-17T22:17:17.343",
"references": [
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/148281"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/148282"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/148286"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/148287"
},
{
"source": "product-security@apple.com",
"url": "https://support.apple.com/en-us/149036"
},
{
"source": "product-security@apple.com",
"url": "https://support.apple.com/en-us/149037"
},
{
"source": "product-security@apple.com",
"url": "https://support.apple.com/en-us/149038"
}
],
"sourceIdentifier": "product-security@apple.com",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-416"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| Vendor vendor | NVD | Applereceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Safari",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.6.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "iOS and iPadOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "18.7.10",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "26.6.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "macOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.6.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "tvOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "27",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "visionOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "27",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "watchOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "27",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"source": "product-security@apple.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E28B5C94-2DF4-4601-B097-582626C761AA",
"versionEndExcluding": "26.6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F413C997-517E-4C4F-9506-B7295E94CFFD",
"versionEndExcluding": "18.7.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "79392FA7-F634-496F-866F-6D054133D23B",
"versionEndExcluding": "26.6.1",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "23D4A4CC-51AE-44CA-A211-5B1A7445E45B",
"versionEndExcluding": "18.7.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8C87B1B6-8A8F-4165-BC18-DE36DE5891C9",
"versionEndExcluding": "26.6.1",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ECE169FD-8BEB-45FE-82CE-FC98AD8EB3CA",
"versionEndExcluding": "26.6.2",
"versionStartIncluding": "26.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process crash."
}
],
"id": "CVE-2026-64715",
"lastModified": "2026-09-14T21:17:14.173",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-64715",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-18T13:21:36.342847Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-08-17T22:17:17.343",
"references": [
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/148281"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/148282"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/148286"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/148287"
},
{
"source": "product-security@apple.com",
"url": "https://support.apple.com/en-us/149036"
},
{
"source": "product-security@apple.com",
"url": "https://support.apple.com/en-us/149037"
},
{
"source": "product-security@apple.com",
"url": "https://support.apple.com/en-us/149038"
}
],
"sourceIdentifier": "product-security@apple.com",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-416"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
vulnerability
| webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash zetlyn/cve-redhat · 2026-08-17 | cvss 8.8 cwe CWE-416 packages webkit2gtk3-0:2.54.0-1.el9_8 severity important | source |
| A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process crash. zetlyn/cve-nvd · 2026-08-17 | cvss 6.5 product Safari status Modified vendor Apple | source |