CVE-2026-20664General(apple / ipados)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • safari

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-25); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_osmacossafarivisionos

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-25: 1Mentions · 2026-04-24: 1Patch / Workaround · 2026-04-24: 1Technical Details · 2026-04-24: 103-2504-24
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-251
General1
2026-04-241
Disclosure1
Full discourse2 posts
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-20664: Safari Same-Origin Policy bypass allows cross-origin data theft from any website via WebAssembly memory corruption and Fetch API abuse. AI-assisted exploit development demonstrates new threat model for browser security. Technical breakdown: • Bug in WebAssembly.Memory refresh logic leaves stale pointer to freed Gigacage allocation after memory.grow() • Response.clone() during loading bypasses opaque response checks, materializing cross-origin data into renderer ArrayBuffers • Exploit chain: create stale WASM buffer → trigger cross-origin fetch with credentials → clone response → reclaim freed pages → read sensitive data • about:blank popup context bypasses Safari's cookie blocking for reliable credential inclusion • Affects all websites - visiting malicious page can leak tokens, session data from victim domains Patched in iOS/iPadOS 26.4 and macOS Tahoe 26.4. Hunt for unusual WebAssembly usage patterns combined with cross-origin requests, especially from popup contexts. #DFIR_Radar

    Post summary

    The post announces a newly disclosed Safari Same‑Origin Policy bypass, details the technical exploitation chain, and lists official patches for affected OS versions.

    20001269
    1.7K followersView on X
  • VulDB 🛡@vuldb
    General

    There is a new vulnerability with elevated criticality in Apple Safari and other products (CVE-2026-20664) https://vuldb.com/?id.352906

    Post summary

    The text merely announces the existence of a new high‑severity vulnerability, CVE‑2026‑20664, in Safari and other products, with a reference to a vulnerability database page but provides no further detail.

    0000091
    2.1K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
Appapplesafari---
OSapplevisionos---

Explore more