Threat intelligence dashboard
CVE-2026-65390high

Vulnerability record

An integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.

Risk score

8.8

CVSS 3.1

Vendor
Apple
Product
Safari, iOS and iPadOS, macOS, tvOS, visionOS, watchOS
CWE
CWE-190
Published
Sep 14, 2026
Updated
Sep 16, 2026
CISA KEV
Not flagged

Affected products and versions

Safari

Apple

Version / rangeStatusType
0 to before 26.6.1affectedcustom

iOS and iPadOS

Apple

Version / rangeStatusType
0 to before 26.6.1affectedcustom

macOS

Apple

Version / rangeStatusType
0 to before 26.6.2affectedcustom

tvOS

Apple

Version / rangeStatusType
0 to before 27affectedcustom

visionOS

Apple

Version / rangeStatusType
0 to before 27affectedcustom

watchOS

Apple

Version / rangeStatusType
0 to before 27affectedcustom

Technical metrics

8.8

CVSS 3.1

Severity
high
Source
CISA-ADP
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H