webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash

cve CVE-2026-65351 2 sources, 2 claims · Watch

Red Hat writes:
webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash the claim

What it is to other things

affectsapple/ipados
NVD
affectsapple/iphone_os
NVD
affectsapple/macos
NVD
affectsapple/safari
NVD
made_byapple
NVD

What each source says

PropertySourceSaidMeans here
Cvss
cvss
conflict
NVD4.3
receipt
Source
NVD
Its words
4.3
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Safari",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.6.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "18.7.10",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.6.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.6.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "visionOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E28B5C94-2DF4-4601-B097-582626C761AA",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DFD48325-D4E4-40C9-B64B-DB5F12A3AF0F",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "2CC8252A-05E1-415B-81AF-0C99BEC864AA",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "ECE169FD-8BEB-45FE-82CE-FC98AD8EB3CA",
                "versionEndExcluding": "26.6.2",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash."
      }
    ],
    "id": "CVE-2026-65351",
    "lastModified": "2026-09-14T21:17:20.147",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-65351",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-18T13:00:05.468201Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-17T22:17:25.580",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148281"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148282"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148286"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/148287"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/149038"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-703"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss
cvss
conflict
Red Hat8.8
receipt
Source
Red Hat
Its words
8.8
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-65351",
  "CWE": "CWE-120",
  "advisories": [
    "RHSA-2026:69098"
  ],
  "affected_packages": [
    "webkit2gtk3-0:2.54.0-1.el9_8"
  ],
  "bugzilla": "2524585",
  "bugzilla_description": "webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash",
  "cvss3_score": "8.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-17T21:31:25Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-65351.json",
  "severity": "important"
}
—
Cwe
cwe
Red HatCWE-120
receipt
Source
Red Hat
Its words
CWE-120
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-65351",
  "CWE": "CWE-120",
  "advisories": [
    "RHSA-2026:69098"
  ],
  "affected_packages": [
    "webkit2gtk3-0:2.54.0-1.el9_8"
  ],
  "bugzilla": "2524585",
  "bugzilla_description": "webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash",
  "cvss3_score": "8.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-17T21:31:25Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-65351.json",
  "severity": "important"
}
—
Packages
packages
Red Hatwebkit2gtk3-0:2.54.0-1.el9_8
receipt
Source
Red Hat
Its words
webkit2gtk3-0:2.54.0-1.el9_8
Read by
field:affected_packages[]
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-65351",
  "CWE": "CWE-120",
  "advisories": [
    "RHSA-2026:69098"
  ],
  "affected_packages": [
    "webkit2gtk3-0:2.54.0-1.el9_8"
  ],
  "bugzilla": "2524585",
  "bugzilla_description": "webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash",
  "cvss3_score": "8.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-17T21:31:25Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-65351.json",
  "severity": "important"
}
—
Product
product
NVDSafari
receipt
Source
NVD
Its words
Safari
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
2026-09-29 17:49 UTCSafari
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Safari",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.6.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "18.7.10",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.6.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.6.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "visionOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E28B5C94-2DF4-4601-B097-582626C761AA",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DFD48325-D4E4-40C9-B64B-DB5F12A3AF0F",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "2CC8252A-05E1-415B-81AF-0C99BEC864AA",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "ECE169FD-8BEB-45FE-82CE-FC98AD8EB3CA",
                "versionEndExcluding": "26.6.2",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash."
      }
    ],
    "id": "CVE-2026-65351",
    "lastModified": "2026-09-14T21:17:20.147",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-65351",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-18T13:00:05.468201Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-17T22:17:25.580",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148281"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148282"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148286"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/148287"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/149038"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-703"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
Red Hatimportant
A flaw that can easily compromise confidentiality, integrity or availability.
receipt
Source
Red Hat
Its words
important
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-65351",
  "CWE": "CWE-120",
  "advisories": [
    "RHSA-2026:69098"
  ],
  "affected_packages": [
    "webkit2gtk3-0:2.54.0-1.el9_8"
  ],
  "bugzilla": "2524585",
  "bugzilla_description": "webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash",
  "cvss3_score": "8.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-17T21:31:25Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-65351.json",
  "severity": "important"
}
high
Status
status
NVDModified
receipt
Source
NVD
Its words
Modified
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Safari",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.6.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "18.7.10",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.6.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.6.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "visionOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E28B5C94-2DF4-4601-B097-582626C761AA",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DFD48325-D4E4-40C9-B64B-DB5F12A3AF0F",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "2CC8252A-05E1-415B-81AF-0C99BEC864AA",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "ECE169FD-8BEB-45FE-82CE-FC98AD8EB3CA",
                "versionEndExcluding": "26.6.2",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash."
      }
    ],
    "id": "CVE-2026-65351",
    "lastModified": "2026-09-14T21:17:20.147",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-65351",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-18T13:00:05.468201Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-17T22:17:25.580",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148281"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148282"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148286"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/148287"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/149038"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-703"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDApple
receipt
Source
NVD
Its words
Apple
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
2026-09-29 17:49 UTCApple
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Safari",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.6.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "18.7.10",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.6.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.6.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "visionOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E28B5C94-2DF4-4601-B097-582626C761AA",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DFD48325-D4E4-40C9-B64B-DB5F12A3AF0F",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "2CC8252A-05E1-415B-81AF-0C99BEC864AA",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "ECE169FD-8BEB-45FE-82CE-FC98AD8EB3CA",
                "versionEndExcluding": "26.6.2",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash."
      }
    ],
    "id": "CVE-2026-65351",
    "lastModified": "2026-09-14T21:17:20.147",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-65351",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-18T13:00:05.468201Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-17T22:17:25.580",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148281"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148282"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148286"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/148287"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/149038"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-703"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
zetlyn/cve-redhat · 2026-08-17
cvss 8.8 cwe CWE-120 packages webkit2gtk3-0:2.54.0-1.el9_8 severity important source
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
zetlyn/cve-nvd · 2026-08-17
cvss 4.3 product Safari status Modified vendor Apple source