Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-65391
Apple Safari vulnerability analysis and mitigation

Overview

CVE-2026-65391 is an out-of-bounds write vulnerability in Apple's WebRTC component (tracked under WebKit Bugzilla: 322761) that can lead to memory corruption when processing maliciously crafted web content. It affects Safari prior to 26.6.1, iOS and iPadOS prior to 26.6.1, macOS Tahoe prior to 26.6.2, tvOS prior to 27, visionOS prior to 27, and watchOS prior to 27. The vulnerability was discovered by researcher Myungyong Lee and disclosed by Apple on September 14, 2026. The CVSS base score is currently listed as 0.0 (pending full NVD scoring), with Feedly estimating severity as HIGH (Apple Advisory iOS/iPadOS, Apple Advisory Safari, Apple Advisory tvOS).

Technical details

The vulnerability is classified as an out-of-bounds write (CWE-787) within Apple's WebRTC implementation, addressed via improved bounds checking. An attacker can exploit this by serving maliciously crafted web content — such as a specially constructed webpage — that triggers improper memory writes in the WebRTC processing pipeline when rendered by a vulnerable browser or WebKit-based component. No user interaction beyond visiting or loading the malicious content is required, making this a network-accessible, low-complexity attack. The fix was applied across all affected Apple platforms in the September 14, 2026 security update cycle (Apple Advisory macOS, Apple Advisory iOS/iPadOS).

Impact

Successful exploitation may result in memory corruption, which could enable arbitrary code execution in the context of the browser or WebKit process. An unauthenticated remote attacker can trigger this vulnerability by luring a target to visit a malicious website, potentially leading to full compromise of the affected process. Across the broad range of affected platforms — iPhone, iPad, Mac, Apple TV, Apple Watch, and Apple Vision Pro — the impact extends to a wide user base, with confidentiality, integrity, and availability all potentially affected (Apple Advisory Safari, Apple Advisory tvOS).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is 0.0, reflecting low current exploitation probability. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Mitigation and workarounds

Apple has released patches addressing CVE-2026-65391 across all affected platforms. Users should update to the following versions or later: Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27. As an interim workaround where immediate patching is not possible, restricting browsing to trusted websites only can reduce exposure. Updates can be applied via System Settings > Software Update on macOS, or Settings > General > Software Update on iOS/iPadOS (Apple Advisory iOS/iPadOS, Apple Advisory macOS, Apple Advisory Safari).

Community reactions

The SANS Internet Storm Center noted the September 14, 2026 Apple update cycle in a diary entry titled "Apple Updates Everything," highlighting the breadth of fixes across Apple's product lineup (SANS ISC). No significant independent researcher commentary or social media discussion specific to CVE-2026-65391 has been identified beyond standard patch coverage.

Additional resources


SourceThis report was generated using AI

Related Apple Safari vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-65391HIGH8.8
  • Apple Safari logoApple Safari
  • WebRTC
NoYesSep 14, 2026
CVE-2026-84635MEDIUM6.5
  • Apple Safari logoApple Safari
  • webkitgtk4-devel
NoYesSep 14, 2026
CVE-2026-86897MEDIUM5.5
  • Apple Safari logoApple Safari
  • Safe Browsing
NoYesSep 14, 2026
CVE-2026-86898MEDIUM5.4
  • Apple Safari logoApple Safari
  • WebKit
NoYesSep 14, 2026
CVE-2026-84518MEDIUM4.3
  • Apple Safari logoApple Safari
  • cpe:2.3:a:apple:safari
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management