Apple Security Updates

WebKit CVEs from Apple's Safari security release pages, cross-referenced to the public WebKit fix commit and, when covered, to the WebKit Weekly analysis of that fix.

Matching is by WebKit Bugzilla number — Apple exposes it on every WebKit CVE entry, and WebKit commits include the same ID as a bugs.webkit.org/show_bug.cgi?id=… reference. Unmatched CVEs are shown too: they usually mean the fix commit is still under Bugzilla embargo.

5 Safari releases 49 WebKit CVEs 40 matched to a commit 40 covered in a report
Safari 27 September 14, 2026 · 3 WebKit CVEs ·3 covered ↗
Safari 26.6.1 August 18, 2026 · 11 WebKit CVEs ·8 covered ↗
CVE-2026-64782

Processing maliciously crafted web content may lead to an unexpected Safari crash

A memory corruption vulnerability was addressed with improved locking.

Bugzilla 321480 Fix not yet public
Credit: Charles Kern, Seonwook Kim, Shubham Chaskar, lattice, Josef Korbel
CVE-2026-64781

Processing maliciously crafted web content may lead to an unexpected Safari crash

The issue was addressed with improved input validation.

Bugzilla 321484 Fix not yet public
Credit: Thomas Guillem
CVE-2026-65351

Processing maliciously crafted web content may lead to an unexpected Safari crash

This issue was addressed through improved state management.

Bugzilla 321517 Fix not yet public
Credit: Niels Hofmans
Safari 26.6 July 27, 2026 · 7 WebKit CVEs ·7 covered ↗
CVE-2026-64783 UAF

Processing maliciously crafted web content may lead to an unexpected Safari crash

A use-after-free issue was addressed with improved memory management.

Credit: Luke Francis, Francisco Alonso (@revskills), Shubham Chaskar, Jiyong Yang (@Sy2n0), 杉山 壮太, lattice, Behzad Najjarpour Jabbari (@_G4ru_), Junyeong Lee, Mooth.ai, OGINOME Tomohito, Using GLM From Z.AI, Gia Bui (@yabeow) from Calif.io
Safari 26.5.2 June 29, 2026 · 17 WebKit CVEs ·13 covered ↗
CVE-2026-43735

A malicious website may exfiltrate data cross-origin

The issue was addressed with improved checks.

Bugzilla 313357 Fix not yet public
Credit: Gurpreet Shergill, Merrick Hare, Drinor Selmanaj (Sentry), Khai Tran, John Lussier, Rhyru9, Kwak Kiyong, Song Nuri
CVE-2026-43734

Processing maliciously crafted web content may lead to an unexpected process crash

A use-after-free issue was addressed with improved memory management.

Bugzilla 313693 Fix not yet public
Credit: Jonathan Alush-Aben
CVE-2026-43727 UAF

Processing maliciously crafted web content may lead to an unexpected Safari crash

A use-after-free issue was addressed with improved memory management.

Credit: Tommy DeVoss from Braze Security Team (@thedawgyg), Gia Bui (@yabeow) from Calif.io, Gurpreet Shergill
CVE-2026-43663 UAF

Processing maliciously crafted web content may lead to an unexpected process crash

The issue was addressed with improved memory handling.

Credit: stratan (@5tratan) of Almamater Technologies, Soyeon Park, Amy Burnett, Khai Tran, sherkito, Kota Toda, HexRabbit (@h3xr4bb1t) and NiNi (@terrynini38514) of DEVCORE Research Team, Using GLM From Z.AI, Tristan Madani (@TristanInSec) from Talence Security, Brian Carpenter
CVE-2026-43716 UAF

Processing maliciously crafted web content may lead to an unexpected Safari crash

The issue was addressed with improved memory handling.

Credit: Maher Azzouzi, Tuan and Duc from Calif.io, OpenAI Codex Security - Amy Burnett, Evan Lambert
CVE-2026-43676

Processing maliciously crafted web content may lead to an unexpected Safari crash

An out-of-bounds access issue was addressed with improved bounds checking.

Bugzilla 317231 Fix not yet public
Credit: Mateusz Krzywicki (iVerify.io), dr3dd, Tommy DeVoss from Braze Security Team (@thedawgyg)
CVE-2026-43707

Processing maliciously crafted web content may lead to an unexpected process crash

A memory corruption issue was addressed with improved memory handling.

Bugzilla 315951 Fix not yet public
Credit: stratan (@5tratan) of Almamater Technologies, OpenAI Codex Security - Amy Burnett
Safari 26.5 May 13, 2026 · 11 WebKit CVEs ·9 covered ↗
CVE-2026-28883

Processing maliciously crafted web content may lead to an unexpected process crash

A use-after-free issue was addressed with improved memory management.

Bugzilla 313939 Fix not yet public
Credit: kwak kiyong / kakaogames
CVE-2026-28917

Processing maliciously crafted web content may lead to an unexpected process crash

The issue was addressed with improved input validation.

Bugzilla 310527 Fix not yet public
Credit: Vitaly Simonovich