Sceawere

Vulnerability Detail

CVE-2026-65337UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Safari Denial of Service Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
19h ago
Vendor
Apple
Product
iOS and iPadOS
Attack Type
Processing maliciously crafted web content may lead to an unexpected Safari crash
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-17T22:17:24.650Z",
  "pubdate": "2026-08-17T22:17:24.650Z",
  "executiveSummary": "This vulnerability involves a denial of service condition in the Safari component across multiple Apple operating systems, specifically leading to an unexpected application crash. The root issue stems from improper state management within the browser engine when handling specific data structures. The primary impact of successful exploitation is the unexpected termination of the Safari application, resulting in a disruption of user workflows and potential loss of unsaved web session data. Affected systems include iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2. The risk implications are generally restricted to availability disruption rather than arbitrary code execution, privilege escalation, or direct data exfiltration. Attacker capabilities require the ability to deliver or host maliciously crafted web content, such as through a compromised or attacker-controlled website, or via a man-in-the-middle injection. Exploitation requirements mandate that a user navigates to or processes the malicious web content using an unpatched instance of the vulnerable software, triggering the flawed state handling logic.",
  "technicalDetails": "The vulnerability resides within the state management subsystem of the Safari web processing engine, which fails to properly maintain or transition application states when parsing complex or anomalous inputs. Specifically, when the browser encounters maliciously crafted web content containing structured data designed to exploit edge cases in state transitions, internal consistency checks fail, resulting in an unhandled exception or memory corruption event that forces the application to terminate unexpectedly.\nThe exploitation method relies on supplying a specially crafted payload via web content—such as HTML, JavaScript, cascading style sheets, or embedded media—that forces the affected component into an invalid or unexpected operational state. The attack flow begins when a user accesses a malicious URL or views compromised web resources through Safari. Upon parsing the malicious constructs, the browser's rendering or processing engine encounters the anomalous input, triggering the flawed state management logic. Because the application cannot safely recover from the invalid state, it crashes to prevent further undefined behavior.\nThe vulnerable component is the web content processing pipeline within Safari. Affected versions explicitly documented include iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2. The vulnerability can be triggered remotely over the network without requiring prior authentication or user interaction beyond the initial navigation to the malicious content. No specific local privilege requirements are needed to initiate the attack, as it operates within the standard execution context of the browser. Post-exploitation impact is limited to the immediate denial of service caused by the crash of the Safari process, with no direct indication of persistent system compromise, arbitrary code execution, or unauthorized access to underlying operating system resources."
}
CVE-2026-65337: Safari Denial of Service Vulnerability (MEDIUM Severity, CVSS: 4.3) - Sceawere