Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-65335

CVE-2026-65335: Apple iPadOS Safari DoS Vulnerability

CVE-2026-65335 is a denial of service vulnerability in Apple iPadOS Safari that causes unexpected browser crashes when processing malicious web content. This article covers technical details, affected versions, and mitigation.

Updated:

CVE-2026-65335 Overview

CVE-2026-65335 is a state management vulnerability affecting Apple Safari and multiple Apple operating systems. Processing maliciously crafted web content can trigger an unexpected Safari crash, resulting in denial of service on affected devices. Apple addressed the flaw through improved state management in Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2. The vulnerability is categorized under [CWE-119] (Improper Restriction of Operations within the Bounds of a Memory Buffer). Exploitation requires user interaction, typically by visiting a malicious webpage.

Critical Impact

A remote attacker can crash Safari on unpatched Apple devices by serving specially crafted web content, disrupting browser availability.

Affected Products

  • Apple iOS and iPadOS (versions prior to 18.7.10 and 26.6.1)
  • Apple macOS Tahoe (versions prior to 26.6.2)
  • Apple Safari (versions prior to 26.6.1)

Discovery Timeline

  • 2026-08-17 - CVE-2026-65335 published to NVD
  • 2026-08-18 - Last updated in NVD database

Technical Details for CVE-2026-65335

Vulnerability Analysis

The flaw resides in the web content processing path used by Safari and the underlying rendering stack on Apple operating systems. Improper state management during the handling of crafted web content leads to a memory boundary condition, mapped to [CWE-119]. When the affected code path processes attacker-controlled input, internal state assumptions break and the browser process terminates unexpectedly.

The impact is limited to availability. There is no indication of memory disclosure or code execution associated with this issue. Successful exploitation requires the victim to load attacker-controlled content, satisfying the user interaction requirement in the CVSS vector.

Root Cause

Apple's advisory attributes the fix to improved state management. State management defects in browser engines typically arise when object lifetimes, parser states, or rendering pipeline transitions are not consistently tracked across asynchronous events. In this case, the inconsistency allows crafted content to drive the engine into an invalid state that violates memory buffer restrictions.

Attack Vector

Exploitation is network-based and requires user interaction. An attacker hosts malicious web content on a controlled site or injects it into a compromised site. When the target opens the page in Safari on an unpatched device, the browser process crashes. Repeated exploitation can prevent normal browsing until the underlying content is avoided or the device is patched.

No verified proof-of-concept code is publicly available for this issue. See the Apple Support advisory 148286 for vendor technical details.

Detection Methods for CVE-2026-65335

Indicators of Compromise

  • Repeated unexpected Safari process terminations on iOS, iPadOS, or macOS devices correlated with visits to specific URLs.
  • Crash reports referencing WebKit or Safari components generated shortly after loading external web content.
  • Endpoint telemetry showing Safari relaunches following navigation to untrusted domains.

Detection Strategies

  • Collect and analyze mobile and macOS crash logs for Safari and WebKit process terminations tied to browsing activity.
  • Correlate web proxy logs with device crash events to identify URLs that consistently trigger browser failures.
  • Monitor for outdated Safari and OS versions across the fleet using inventory data.

Monitoring Recommendations

  • Track Safari and OS build versions through mobile device management (MDM) to flag devices below patched builds.
  • Alert on abnormal Safari crash rates per user or per device over rolling windows.
  • Feed browser and OS telemetry into a centralized data lake for cross-source correlation with URL categorization.

How to Mitigate CVE-2026-65335

Immediate Actions Required

  • Update affected devices to Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, or macOS Tahoe 26.6.2 as applicable.
  • Enforce automatic OS updates through MDM policies on managed Apple devices.
  • Advise users to avoid untrusted links until patch deployment completes.

Patch Information

Apple resolved the issue through improved state management. Apply the vendor-supplied updates documented in Apple Support Article 148281, Apple Support Article 148282, Apple Support Article 148286, and Apple Support Article 148287.

Workarounds

  • Use an alternative up-to-date browser on macOS until Safari is patched.
  • Restrict browsing to trusted domains through enterprise web filtering.
  • Enable Lockdown Mode on high-risk iOS and macOS devices to reduce browser attack surface.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.