About the security content of Safari 26.6
This document describes the security content of Safari 26.6.
About Apple security updates
For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available. Recent releases are listed on the Apple security releases page.
Apple security documents reference vulnerabilities by CVE-ID when possible.
For more information about security, see the Apple Product Security page.
Safari 26.6
Released July 27, 2026
Safari
Available for: macOS Sonoma and macOS Sequoia
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state management.
CVE-2026-43792: Ilya Andr (andrd3v)
WebKit
Available for: macOS Sonoma and macOS Sequoia
Impact: Processing maliciously crafted web content may result in the disclosure of process memory
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 308046
CVE-2026-43740: Arni Hardarson, Nathaniel Oh (@calysteon)
WebKit
Available for: macOS Sonoma and macOS Sequoia
Impact: Websites may know if the user has visited a given link
Description: This issue was addressed with improved checks.
WebKit Bugzilla: 316827
CVE-2026-64713: Kwak Kiyong, Song Nuri
WebKit
Available for: macOS Sonoma and macOS Sequoia
Impact: Visiting a website that frames malicious content may lead to UI spoofing
Description: The issue was addressed with improved UI.
WebKit Bugzilla: 311660
CVE-2026-64730: Kagami Rosylight of Mozilla
WebKit
Available for: macOS Sonoma and macOS Sequoia
Impact: Maliciously crafted web content may violate iframe sandboxing policy
Description: A permissions issue was addressed with improved validation.
WebKit Bugzilla: 313220
CVE-2026-64728: an anonymous researcher
WebKit
Available for: macOS Sonoma and macOS Sequoia
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 313521
CVE-2026-64783: 杉山 壮太, lattice, Behzad Najjarpour Jabbari (@_G4ru_), Junyeong Lee, Mooth.ai, OGINOME Tomohito, Using GLM From Z.AI, Gia Bui (@yabeow) from Calif.io
WebKit
Available for: macOS Sonoma and macOS Sequoia
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A memory corruption issue was addressed with improved state management.
WebKit Bugzilla: 315082
CVE-2026-64757: Milad Nasr and Nicholas Carlini with Claude, Anthropic
WebKit
Available for: macOS Sonoma and macOS Sequoia
Impact: Visiting a website may lead to an app denial-of-service
Description: This issue was addressed through improved state management.
WebKit Bugzilla: 316816
CVE-2026-43804: Heiko Kiesel of SEEMOO, TU Darmstadt
WebKit
Available for: macOS Sonoma and macOS Sequoia
Impact: An app may be able to read files outside of its sandbox
Description: An access issue was addressed with improved access restrictions.
WebKit Bugzilla: 314867
CVE-2026-43821: Brian Carpenter
WebKit Canvas
Available for: macOS Sonoma and macOS Sequoia
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 313935
CVE-2026-64718: OGINOME Tomohito, an anonymous researcher
WebRTC
Available for: macOS Sonoma and macOS Sequoia
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: An out-of-bounds access issue was addressed with improved bounds checking.
WebKit Bugzilla: 319404
CVE-2026-64719: Shaheen Fazim
Additional recognition
Safari Downloads
We would like to acknowledge Alfaz Hossain for their assistance.
WebKit
We would like to acknowledge Jaya Surya Kommireddy, Jaya surya Kommireddy, Lukas Knittel (@kunte_ctf) of Ruhr-University Bochum, Nikos Fanourakis of Technical University of Crete, Sotiris Ioannidis of Technical University of Crete, Panagiotis Ilia of Cyprus University of Technology, and Kostas Drakonakis of Technical University of Crete, Tony Gorez (@tonygo_) for Reverse Society, Vitaly Simonovich, Youngjoon Kim of Team-Atlanta & sslab at Georgia Tech, s3zer0 for their assistance.
WebKit Canvas
We would like to acknowledge Codex Security - Khai Tran, Daisuke Hatakeyama and Ryohei Ueki (@SYZD Research), David Bors at Snyk Security Labs, Giovanni Vignone and Robert van Eijk of Octane Security (octane.security), Kwak Kiyong, Song nuri, Luat Nguyen (CyberJutsu Academy), Tom Van Goethem, an anonymous researcher, dr3dd for their assistance.
WebKit Storage
We would like to acknowledge Gurpreet Shergill, Luke Francis, Milad Nasr and Nicholas Carlini with Claude, Anthropic, Oleh Konko of 1seal (1seal.org), Vitaly Simonovich for their assistance.
Information about products not manufactured by Apple, or independent websites not controlled or tested by Apple, is provided without recommendation or endorsement. Apple assumes no responsibility with regard to the selection, performance, or use of third-party websites or products. Apple makes no representations regarding third-party website accuracy or reliability. Contact the vendor for additional information.