About the security content of Safari 26.6

This document describes the security content of Safari 26.6.

About Apple security updates

For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available. Recent releases are listed on the Apple security releases page.

Apple security documents reference vulnerabilities by CVE-ID when possible.

For more information about security, see the Apple Product Security page.

Safari 26.6

Released July 27, 2026

Safari

Available for: macOS Sonoma and macOS Sequoia

Impact: An app may be able to access sensitive user data

Description: An authorization issue was addressed with improved state management.

CVE-2026-43792: Ilya Andr (andrd3v)

WebKit

Available for: macOS Sonoma and macOS Sequoia

Impact: Processing maliciously crafted web content may result in the disclosure of process memory

Description: The issue was addressed with improved memory handling.

WebKit Bugzilla: 308046

CVE-2026-43740: Arni Hardarson, Nathaniel Oh (@calysteon)

WebKit

Available for: macOS Sonoma and macOS Sequoia

Impact: Websites may know if the user has visited a given link

Description: This issue was addressed with improved checks.

WebKit Bugzilla: 316827

CVE-2026-64713: Kwak Kiyong, Song Nuri

WebKit

Available for: macOS Sonoma and macOS Sequoia

Impact: Visiting a website that frames malicious content may lead to UI spoofing

Description: The issue was addressed with improved UI.

WebKit Bugzilla: 311660

CVE-2026-64730: Kagami Rosylight of Mozilla

WebKit

Available for: macOS Sonoma and macOS Sequoia

Impact: Maliciously crafted web content may violate iframe sandboxing policy

Description: A permissions issue was addressed with improved validation.

WebKit Bugzilla: 313220

CVE-2026-64728: an anonymous researcher

WebKit

Available for: macOS Sonoma and macOS Sequoia

Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash

Description: A use-after-free issue was addressed with improved memory management.

WebKit Bugzilla: 313521

CVE-2026-64783: 杉山 壮太, lattice, Behzad Najjarpour Jabbari (@_G4ru_), Junyeong Lee, Mooth.ai, OGINOME Tomohito, Using GLM From Z.AI, Gia Bui (@yabeow) from Calif.io

WebKit

Available for: macOS Sonoma and macOS Sequoia

Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash

Description: A memory corruption issue was addressed with improved state management.

WebKit Bugzilla: 315082

CVE-2026-64757: Milad Nasr and Nicholas Carlini with Claude, Anthropic

WebKit

Available for: macOS Sonoma and macOS Sequoia

Impact: Visiting a website may lead to an app denial-of-service

Description: This issue was addressed through improved state management.

WebKit Bugzilla: 316816

CVE-2026-43804: Heiko Kiesel of SEEMOO, TU Darmstadt

WebKit

Available for: macOS Sonoma and macOS Sequoia

Impact: An app may be able to read files outside of its sandbox

Description: An access issue was addressed with improved access restrictions.

WebKit Bugzilla: 314867

CVE-2026-43821: Brian Carpenter

WebKit Canvas

Available for: macOS Sonoma and macOS Sequoia

Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash

Description: A use-after-free issue was addressed with improved memory management.

WebKit Bugzilla: 313935

CVE-2026-64718: OGINOME Tomohito, an anonymous researcher

WebRTC

Available for: macOS Sonoma and macOS Sequoia

Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash

Description: An out-of-bounds access issue was addressed with improved bounds checking.

WebKit Bugzilla: 319404

CVE-2026-64719: Shaheen Fazim

Additional recognition

Safari Downloads

We would like to acknowledge Alfaz Hossain for their assistance.

WebKit

We would like to acknowledge Jaya Surya Kommireddy, Jaya surya Kommireddy, Lukas Knittel (@kunte_ctf) of Ruhr-University Bochum, Nikos Fanourakis of Technical University of Crete, Sotiris Ioannidis of Technical University of Crete, Panagiotis Ilia of Cyprus University of Technology, and Kostas Drakonakis of Technical University of Crete, Tony Gorez (@tonygo_) for Reverse Society, Vitaly Simonovich, Youngjoon Kim of Team-Atlanta & sslab at Georgia Tech, s3zer0 for their assistance.

WebKit Canvas

We would like to acknowledge Codex Security - Khai Tran, Daisuke Hatakeyama and Ryohei Ueki (@SYZD Research), David Bors at Snyk Security Labs, Giovanni Vignone and Robert van Eijk of Octane Security (octane.security), Kwak Kiyong, Song nuri, Luat Nguyen (CyberJutsu Academy), Tom Van Goethem, an anonymous researcher, dr3dd for their assistance.

WebKit Storage

We would like to acknowledge Gurpreet Shergill, Luke Francis, Milad Nasr and Nicholas Carlini with Claude, Anthropic, Oleh Konko of 1seal (1seal.org), Vitaly Simonovich for their assistance.

Information about products not manufactured by Apple, or independent websites not controlled or tested by Apple, is provided without recommendation or endorsement. Apple assumes no responsibility with regard to the selection, performance, or use of third-party websites or products. Apple makes no representations regarding third-party website accuracy or reliability. Contact the vendor for additional information.

Published Date: