
Our researcher @generally_oui reported CVE-2026-64784, an out-of-bounds bug in WebKit fixed in Safari 26.6.1. https://support.apple.com/en-us/148286 In our analysis it reached AAR, AAW in web content process. (exclude PAC) We'll write a detailed write-up on http://oobs.io as soon as this issue become stable. Stay tuned!
Post summary
A researcher reported CVE-2026-64784, an out-of-bounds WebKit defect that has already been fixed in Safari 26.6.1, with no PoC, exploit, or active exploitation mentioned.
