
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20644 is a memory handling vulnerability in Apple's WebKit browser engine that can cause an unexpected process crash when processing maliciously crafted web content. It affects Safari (before 26.3), iOS and iPadOS (before 18.7.5 and before 26.3), macOS Tahoe (before 26.3), and visionOS (before 26.3). The vulnerability was disclosed and patched on February 11, 2026, with credits to HanQing from TSDubhe and Nan Wang (@eternalsakura13) (Apple iOS 26.3, Apple Safari 26.3). It carries a CVSS v3.1 base score of 6.5 (Medium) (Feedly).
The root cause is classified under CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), CWE-416 (Use After Free), and CWE-787 (Out-of-bounds Write), addressed by Apple through improved memory handling in WebKit (WebKit Bugzilla: 303444). The attack vector is network-based and requires user interaction — specifically, a victim must visit or be directed to a maliciously crafted web page. No authentication or special privileges are required on the attacker's side, making this exploitable by any remote party who can lure a user to malicious content (Apple iOS 26.3, Apple visionOS 26.3). No public proof-of-concept code has been identified at this time.
Successful exploitation results in an unexpected process crash of the WebKit rendering process, causing a denial-of-service condition for the affected browser or application. The CVSS scoring reflects a high availability impact with no confidentiality or integrity impact, meaning the primary consequence is application instability rather than data theft or code execution. The vulnerability affects a broad range of Apple devices across iOS, iPadOS, macOS, and visionOS platforms, potentially disrupting web browsing for a large user base (Apple iOS 26.3, Apple Safari 26.3).
Apple has released patches addressing this vulnerability across all affected platforms. Users should update to the following versions or later: Safari 26.3, iOS 18.7.5 or iOS 26.3, iPadOS 18.7.5 or iPadOS 26.3, macOS Tahoe 26.3, and visionOS 26.3. Updates can be applied via the standard Apple software update mechanism (Settings > General > Software Update on iOS/iPadOS; System Settings > General > Software Update on macOS). No configuration-based workarounds have been published by Apple; upgrading to a patched version is the recommended remediation (Apple iOS 26.3, Apple Safari 26.3, Apple macOS Tahoe 26.3).
The vulnerability was part of a broader February 2026 Apple security update that addressed over 90 vulnerabilities across iOS, iPadOS, and macOS, which received coverage from technology media outlets (CyberInsider). Security community discussion was limited given the medium severity and lack of active exploitation. The patch release was noted in security aggregation platforms and Linux distribution advisories as the WebKit fix propagated to downstream projects such as WebKitGTK on Debian, SUSE, Fedora, and Red Hat (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."