
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20664 is a memory handling vulnerability in Apple's WebKit engine that allows processing of maliciously crafted web content to lead to an unexpected process crash. It affects Safari, iOS, iPadOS, macOS Tahoe, and visionOS versions prior to 26.4. The vulnerability was disclosed on March 24, 2026, when Apple released patched versions across all affected platforms. It carries a CVSS v3.1 base score of 4.3 (Medium), though Feedly estimates its category as HIGH (Apple visionOS Advisory, Apple Safari Advisory, Apple iOS/iPadOS Advisory).
The root cause is classified as CWE-787 (Out-of-bounds Write), stemming from improper memory handling within the WebKit rendering engine (WebKit Bugzilla: 306136). An attacker can exploit this by crafting malicious web content — such as a specially constructed webpage — that triggers the out-of-bounds write condition when processed by the WebKit engine, resulting in an unexpected process crash. Exploitation requires user interaction, specifically a user visiting or loading the malicious web content in a vulnerable browser or web view. The vulnerability was credited to multiple researchers: Yeonghyeon Choi, Daniel Rhea, Söhnke Benedikt Fischedick (Tripton), Emrovsky & Switch3301, and Yevhen Pervushyn (Apple iOS/iPadOS Advisory, Apple macOS Advisory).
Successful exploitation causes an unexpected crash of the web content rendering process (e.g., the Safari browser or WebKit-based web view), resulting in a denial-of-service condition for the affected application. There is no evidence of confidentiality or integrity impact — the primary consequence is availability loss limited to the affected process. The scope is unchanged, meaning the crash is contained to the web content process and does not directly enable privilege escalation or lateral movement (Apple Safari Advisory, Apple visionOS Advisory).
com.apple.WebKit.WebContent crash logs in /Library/Logs/DiagnosticReports/ or ~/Library/Logs/DiagnosticReports/) referencing memory access violations or out-of-bounds write conditions.com.apple.WebKit.WebContent process or Safari renderer process without user-initiated action, particularly after visiting an unfamiliar or suspicious URL.Apple has released patches addressing CVE-2026-20664 in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, and visionOS 26.4, all released on March 24, 2026. Users should update their Apple devices to these versions or later via System Settings > General > Software Update (iOS/iPadOS/macOS) or the App Store (Safari on older macOS). No configuration-based workaround is available; updating to the patched version is the only recommended remediation. Additionally, users should exercise caution when visiting untrusted websites as a general precaution (Apple Safari Advisory, Apple iOS/iPadOS Advisory, Apple macOS Advisory, Apple visionOS Advisory).
The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Apple products patched in the March 2026 security updates, including CVE-2026-20664, flagging potential for privilege escalation and other impacts across the product line. The vulnerability also received coverage in Linux security communities due to its presence in WebKitGTK, with multiple downstream advisories issued for Fedora, Debian, Ubuntu, SUSE, Red Hat, Rocky Linux, and AlmaLinux. An Imperva blog post titled "Hacking Safari with GPT-5.4" referenced related WebKit vulnerabilities from this update cycle, drawing broader community attention to the March 2026 Safari security fixes (CIS Advisory, Imperva Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."