PatchSiren cyber security CVE debrief
CVE-2026-64784 Apple CVE debrief
Apple has addressed an out-of-bounds access issue in multiple products, including Safari, iOS, iPadOS, macOS, and visionOS. The issue was fixed in various versions, including Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
- Vendor
- Apple
- Product
- Safari
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-17
- Original CVE updated
- 2026-09-14
- Advisory published
- 2026-08-17
- Advisory updated
- 2026-09-14
Who should care
Defenders responsible for Apple products, especially those exposed to untrusted web content, should assess exposure and prioritize patching. This includes reviewing and updating inventory of Apple devices and systems, and monitoring for unexpected Safari crashes or suspicious web content activity. Defenders should also verify and apply patches for affected Apple products, and review compensating controls for exposed systems while remediation is scheduled,
Why it matters
Defenders should prioritize verifying and applying patches for the affected Apple products, especially for systems and users exposed to untrusted web content, to prevent potential Safari crashes.
- Verify and apply patches to prevent potential Safari crashes
- Monitor for suspicious web content activity
- Update inventory of Apple devices and systems
Technical summary
An out-of-bounds access issue was addressed with improved bounds checking in various Apple products, including Safari, iOS, iPadOS, macOS, and visionOS. Processing maliciously crafted web content may lead to an unexpected Safari crash. The issue was fixed in various versions, including Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27. Defenders should prioritize verifying and applying the available patches for the affected Apple products, especially for systems and users exposed to untrusted web content.
Defensive priority
Defenders should prioritize verifying and applying the available patches for the affected Apple products, especially for systems and users exposed to untrusted web content.
Recommended defensive actions
- Verify and apply patches for affected Apple products
- Review and update inventory of Apple devices and systems
- Monitor for unexpected Safari crashes or suspicious web content activity
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD vulnerability detail provide information on the out-of-bounds access issue addressed by Apple. The fixes are available in various versions of Safari, iOS, iPadOS, macOS, and visionOS.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-64784 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-64784
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-64784 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64784
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://support.apple.com/en-us/148281
[email protected] - Release Notes, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://support.apple.com/en-us/148282
[email protected] - Release Notes, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://support.apple.com/en-us/148286
[email protected] - Release Notes, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://support.apple.com/en-us/148287
[email protected] - Release Notes, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://support.apple.com/en-us/149038
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.