CVE-2026-20664
Apple Safari vulnerability analysis and mitigation

Overview

CVE-2026-20664 is a memory handling vulnerability in Apple's WebKit engine that allows processing of maliciously crafted web content to lead to an unexpected process crash. It affects Safari, iOS, iPadOS, macOS Tahoe, and visionOS versions prior to 26.4. The vulnerability was disclosed on March 24, 2026, when Apple released patched versions across all affected platforms. It carries a CVSS v3.1 base score of 4.3 (Medium), though Feedly estimates its category as HIGH (Apple visionOS Advisory, Apple Safari Advisory, Apple iOS/iPadOS Advisory).

Technical details

The root cause is classified as CWE-787 (Out-of-bounds Write), stemming from improper memory handling within the WebKit rendering engine (WebKit Bugzilla: 306136). An attacker can exploit this by crafting malicious web content — such as a specially constructed webpage — that triggers the out-of-bounds write condition when processed by the WebKit engine, resulting in an unexpected process crash. Exploitation requires user interaction, specifically a user visiting or loading the malicious web content in a vulnerable browser or web view. The vulnerability was credited to multiple researchers: Yeonghyeon Choi, Daniel Rhea, Söhnke Benedikt Fischedick (Tripton), Emrovsky & Switch3301, and Yevhen Pervushyn (Apple iOS/iPadOS Advisory, Apple macOS Advisory).

Impact

Successful exploitation causes an unexpected crash of the web content rendering process (e.g., the Safari browser or WebKit-based web view), resulting in a denial-of-service condition for the affected application. There is no evidence of confidentiality or integrity impact — the primary consequence is availability loss limited to the affected process. The scope is unchanged, meaning the crash is contained to the web content process and does not directly enable privilege escalation or lateral movement (Apple Safari Advisory, Apple visionOS Advisory).

Exploitation steps

  1. Reconnaissance: Identify targets running vulnerable Apple software — Safari, iOS/iPadOS, macOS Tahoe, or visionOS — with versions prior to 26.4, using passive fingerprinting or social engineering.
  2. Craft malicious web content: Develop a webpage or web resource that triggers the out-of-bounds write condition in WebKit's memory handling routines (referencing WebKit Bugzilla: 306136 for the affected code path).
  3. Deliver the payload: Host the malicious page on an attacker-controlled server or distribute a link via phishing, malvertising, or other social engineering channels to induce the target user to visit the page.
  4. Trigger the crash: When the victim's device processes the malicious web content using a vulnerable WebKit version, the out-of-bounds write causes an unexpected process crash, resulting in denial of service for the browser or web view (Apple iOS/iPadOS Advisory, Apple Safari Advisory).

Indicators of compromise

  • Logs: Repeated or unexpected crash reports from the Safari or WebKit process (e.g., com.apple.WebKit.WebContent crash logs in /Library/Logs/DiagnosticReports/ or ~/Library/Logs/DiagnosticReports/) referencing memory access violations or out-of-bounds write conditions.
  • Process: Sudden termination of the com.apple.WebKit.WebContent process or Safari renderer process without user-initiated action, particularly after visiting an unfamiliar or suspicious URL.
  • Network: Connections to unfamiliar or suspicious domains immediately preceding a WebKit process crash, potentially indicating delivery of malicious web content.

Mitigation and workarounds

Apple has released patches addressing CVE-2026-20664 in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, and visionOS 26.4, all released on March 24, 2026. Users should update their Apple devices to these versions or later via System Settings > General > Software Update (iOS/iPadOS/macOS) or the App Store (Safari on older macOS). No configuration-based workaround is available; updating to the patched version is the only recommended remediation. Additionally, users should exercise caution when visiting untrusted websites as a general precaution (Apple Safari Advisory, Apple iOS/iPadOS Advisory, Apple macOS Advisory, Apple visionOS Advisory).

Community reactions

The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Apple products patched in the March 2026 security updates, including CVE-2026-20664, flagging potential for privilege escalation and other impacts across the product line. The vulnerability also received coverage in Linux security communities due to its presence in WebKitGTK, with multiple downstream advisories issued for Fedora, Debian, Ubuntu, SUSE, Red Hat, Rocky Linux, and AlmaLinux. An Imperva blog post titled "Hacking Safari with GPT-5.4" referenced related WebKit vulnerabilities from this update cycle, drawing broader community attention to the March 2026 Safari security fixes (CIS Advisory, Imperva Blog).

Additional resources


SourceThis report was generated using AI

Related Apple Safari vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64757NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64730NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64728NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64719NONEN/A
  • Apple Safari logoApple Safari
  • WebRTC
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management