Sceawere

Vulnerability Detail

CVE-2026-65340UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Safari Web Content Denial of Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
19h ago
Vendor
Apple
Product
iOS and iPadOS
Attack Type
Processing maliciously crafted web content may lead to an unexpected Safari crash
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-17T22:17:24.973Z",
  "pubdate": "2026-08-17T22:17:24.973Z",
  "executiveSummary": "A denial of service vulnerability exists within Safari when processing maliciously crafted web content, potentially leading to an unexpected application crash. The root cause stems from improper state management within the affected web processing engine. The vulnerability impacts multiple Apple operating systems and software versions, specifically iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, and macOS Tahoe 26.6.2. Successful exploitation of this flaw disrupts browser availability and degrades the user experience by forcibly terminating the application session. An attacker must successfully deliver or host maliciously crafted web content to trigger the processing error. Exploitation typically requires user interaction, such as navigating a browser to a malicious URL, viewing compromised web pages, or rendering hostile email content. The risk implications are primarily focused on availability rather than confidentiality or integrity breaches, as remote code execution or privilege escalation vectors are not indicated by the baseline state management defect. Defenses rely on applying vendor-supplied software updates to incorporate the corrected state management logic.",
  "technicalDetails": "The vulnerability is rooted in deficient state management mechanisms governing how the browser engine parses and processes complex or maliciously crafted web content. Within the affected software versions—specifically iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, and macOS Tahoe 26.6.2—the rendering or execution pipeline fails to properly track, validate, or transition internal states when encountering anomalous syntax, structural malformations, or adversarial formatting embedded within web resources. When the parser encounters this unauthorized structural state, unhandled exceptions or memory management faults occur, directly triggering an abrupt termination of the Safari application process. The attack flow begins when an attacker exposes a target user to maliciously crafted web content. This exposure can occur via traditional web browsing, wherein a user navigates to an attacker-controlled website hosting the exploit payload, or through auxiliary vectors such as embedded web views within third-party applications or rendering engines handling incoming network data. Upon ingestion of the malicious web content, the parsing engine attempts to process the elements, leading to the internal state management failure. The vulnerable component lacks sufficient input sanitization and state verification routines to safely handle anomalous execution paths or corrupted object models. No authentication or elevated privileges are required for an attacker to initiate the attack sequence, provided the victim can be induced to process the hostile content over standard network vectors. The immediate post-exploitation impact is strictly confined to a denial of service condition characterized by the sudden crash of the Safari application, disrupting active browsing sessions and potentially leading to localized resource loss."
}
CVE-2026-65340: Safari Web Content Denial of Service (MEDIUM Severity, CVSS: 4.3) - Sceawere