Safari 26.5 fixes WebKit insects that would crash Safari or disclose consumer knowledge

safari ios26.jpg


Apple has revealed the overall checklist of safety fixes for Safari 26.5, together with a WebKit vulnerability that would let maliciously crafted internet content material reveal delicate consumer knowledge. Listed below are the main points.

On that very same day, the corporate launched the overall safety content material for each and every replace, and you’ll be able to in finding extra information about it right here.

Now, Apple has launched the protection content material for Safari 26.5, which contains fixes for 20 WebKit vulnerabilities, in addition to a WebRTC factor that would purpose an sudden procedure crash.

WebKit

To be had for: macOS Sonoma and macOS Sequoia

Affect: Processing maliciously crafted internet content material would possibly save you Content material Safety Coverage from being enforced

Description: A validation factor was once addressed with advanced common sense.

WebKit Bugzilla: 308906

CVE-2026-43660: Cantina

WebKit

To be had for: macOS Sonoma and macOS Sequoia

Affect: Processing maliciously crafted internet content material would possibly save you Content material Safety Coverage from being enforced

Description: The problem was once addressed with advanced enter validation.

WebKit Bugzilla: 308675

CVE-2026-28907: Cantina

WebKit

To be had for: macOS Sonoma and macOS Sequoia

Affect: Processing maliciously crafted internet content material would possibly reveal delicate consumer knowledge

Description: This factor was once addressed with advanced get right of entry to restrictions.

WebKit Bugzilla: 309698

CVE-2026-28962: Luke Francis, Vaagn Vardanian, kwak kiyong / kakaogames, Vitaly Simonovich, Adel Bouachraoui, greenbynox

WebKit

To be had for: macOS Sonoma and macOS Sequoia

Affect: Processing maliciously crafted internet content material would possibly result in an sudden Safari crash

Description: The problem was once addressed with advanced reminiscence dealing with.

WebKit Bugzilla: 307669

CVE-2026-43658: Do Younger Park

WebKit

To be had for: macOS Sonoma and macOS Sequoia

Affect: Processing maliciously crafted internet content material would possibly result in an sudden procedure crash

Description: The problem was once addressed with advanced reminiscence dealing with.

WebKit Bugzilla: 308545

CVE-2026-28905: Yuhao Hu, Yuanming Lai, Chenggang Wu, and Zhe Wang

WebKit Bugzilla: 308707

CVE-2026-28847: DARKNAVY (@DarkNavyOrg), Nameless running with TrendAI 0 Day Initiative, Daniel Rhea

WebKit Bugzilla: 309601

CVE-2026-28904: Luka Rački

WebKit Bugzilla: 310880

CVE-2026-28955: wac and Kookhwan Lee running with TrendAI 0 Day Initiative

WebKit Bugzilla: 310303

CVE-2026-28903: Mateusz Krzywicki (iVerify.io)

WebKit Bugzilla: 309628

CVE-2026-28953: Maher Azzouzi

WebKit Bugzilla: 309861

CVE-2026-28902: Tristan Madani (@TristanInSec) from Talence Safety, Nathaniel Oh (@calysteon)

WebKit Bugzilla: 310207

CVE-2026-28901: Aisle offensive safety analysis crew (Joshua Rogers, Luigino Camastra, Igor Morgenstern, and Guido Vranken), Maher Azzouzi, Ngan Nguyen of Calif.io

WebKit Bugzilla: 311631

CVE-2026-28913: an nameless researcher

WebKit

To be had for: macOS Sonoma and macOS Sequoia

Affect: Processing maliciously crafted internet content material would possibly result in an sudden procedure crash

Description: A use-after-free factor was once addressed with advanced reminiscence control.

WebKit Bugzilla: 313939

CVE-2026-28883: kwak kiyong / kakaogames

WebKit

To be had for: macOS Sonoma and macOS Sequoia

Affect: An app could possibly get right of entry to delicate consumer knowledge

Description: This factor was once addressed with advanced knowledge coverage.

WebKit Bugzilla: 311228

CVE-2026-28958: Cantina

WebKit

To be had for: macOS Sonoma and macOS Sequoia

Affect: Processing maliciously crafted internet content material would possibly result in an sudden procedure crash

Description: The problem was once addressed with advanced enter validation.

WebKit Bugzilla: 310527

CVE-2026-28917: Vitaly Simonovich

WebKit

To be had for: macOS Sonoma and macOS Sequoia

Affect: Processing maliciously crafted internet content material would possibly result in an sudden Safari crash

Description: A use-after-free factor was once addressed with advanced reminiscence control.

WebKit Bugzilla: 310234

CVE-2026-28947: dr3dd

WebKit Bugzilla: 310544

CVE-2026-28946: Gia Bui (@yabeow) from Calif.io, dr3dd, w0wbox

WebKit Bugzilla: 312180

CVE-2026-28942: Milad Nasr and Nicholas Carlini with Claude, Anthropic

WebKit

To be had for: macOS Sonoma and macOS Sequoia

Affect: A malicious iframe would possibly use some other website online’s obtain settings

Description: The problem was once addressed with advanced UI dealing with.

CVE-2026-28971: Khiem Tran

WebKit Bugzilla: 311288

WebRTC

To be had for: macOS Sonoma and macOS Sequoia

Affect: Processing maliciously crafted internet content material would possibly result in an sudden procedure crash

Description: The problem was once addressed with advanced reminiscence dealing with.

WebKit Bugzilla: 311131

CVE-2026-28944: Kenneth Hsu of Palo Alto Networks, Jérôme DJOUDER, dr3dd

In case your Mac is appropriate with Safari 26.5, it could be a good suggestion to remember to’re working the newest model once imaginable.


Leave a Comment

Your email address will not be published. Required fields are marked *