CVE-2026-64715Patch(apple / ipados)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process crash.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • safari

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-08-25); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
ipadosiphone_osmacossafari

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-08-18: 1Mentions · 2026-08-25: 2Mentions · 2026-08-28: 1Mentions · 2026-08-29: 1Patch / Workaround · 2026-08-18: 1Patch / Workaround · 2026-08-25: 1Patch / Workaround · 2026-08-28: 1Technical Details · 2026-08-18: 1Technical Details · 2026-08-25: 2Technical Details · 2026-08-28: 108-1808-2508-2808-29
Signal classification3 categories
Patch
360.0%
Disclosure
120.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-181
Patch1
2026-08-252
Disclosure1Patch1
2026-08-281
Patch1
2026-08-291
General1
Full discourse5 posts
  • Hossein Lotfi@hosselot
    Patch

    Apple Safari JavaScriptCore B3 ReduceStrength select specialization Use-After-Free vulnerability (CVE-2026-64715) fix: https://github.com/WebKit/WebKit/commit/1d5c10e2f9c8f31378c8b14fb71a48423793ce07

    Post summary

    The text announces a patch commit for the Apple Safari JavaScriptCore Use-After-Free vulnerability (CVE-2026-64715).

    15056298.9K
    6.6K followersView on X
  • Hossein Lotfi@hosselot
    Patch

    One vulnerability fixed in macOS Tahoe 26.6.2, iOS 26.6.1, ... : https://support.apple.com/en-us/148281 WebKit [316347]: CVE-2026-64715: RCE (use-after-free)

    Post summary

    Apple released a patch for CVE‑2026‑64715, a WebKit RCE use‑after‑free bug, in macOS Tahoe 26.6.2 and iOS 26.6.1.

    012401617.7K
    6.6K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity CVE-2026-64715: Apple Safari JavaScriptCore B3 Use-After-Free — Detection and R… "The Zero Day Initiative has published ZDI-26-610, disclosing a use-after-free vulnerability in…" 🔗 https://securityarsenal.com/blog/cve-2026-64715-apple-safari-javascriptcore-b3-use-after-free-detection-and-remediation-guide-for-macos-fleets #CyberSecurity #ThreatIntel #critical #zeroday #cve

    Post summary

    The post announces CVE‑2026‑64715, a use‑after‑free flaw in Safari’s JavaScriptCore, and directs readers to a remediation guide, indicating available patching rather than active exploitation or PoC.

    01011220
    29 followersView on X
  • eyer@Butuoyv1Eyer
    General

    @hosselot Hi question out of curiosity (no expert at this) can you escalate privileges with this? (CVE-2026-64715) or was it not researched that far?

    Post summary

    The tweet asks whether CVE-2026-64715 allows privilege escalation, but provides no evidence of exploitation, technical details, or mitigations.

    0000081
    98 followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Apple Safari JavaScriptCore B3 ReduceStrength Phase Use-After-Free Remote Code Execution Vulnerability (CVE-2026-64715) https://www.systemtek.co.uk/2026/08/apple-safari-javascriptcore-b3-reducestrength-phase-use-after-free-remote-code-execution-vulnerability-cve-2026-64715/ via @SystemTek_UK

    Post summary

    The text announces the discovery of CVE-2026-64715, a use‑after‑free RCE flaw in Apple Safari’s JavaScriptCore, and provides a link to a detailed disclosure.

    0000054
    1.8K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
Appapplesafari---

Explore more