Back to search

Apple

Safari

See the latest tracked release, confirm when it was published, and subscribe for update emails.

Current version
Last checked: 2026-09-04

18.6

Release date
July 30, 2025
Security status
Current version appears affected by 36 high-severity CVEs.

Source

SOFA Apple Feed

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
18.6 2025-07-30 Release Notes

Vulnerability tracking

versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.

Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.

CVE Severity Published Status Summary
CVE-2026-43670 HIGH (8.8) 2026-08-25 Current versionaffected

A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-43794 HIGH (8.8) 2026-08-17 Current versionaffected

A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6.1
CVE-2026-64783 HIGH (8.8) 2026-07-27 Current versionaffected

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64757 HIGH (8.8) 2026-07-27 Current versionaffected

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64713 HIGH (8.1) 2026-07-27 Current versionaffected

This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Websites may know if the user has visited a given link.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64719 HIGH (8.1) 2026-07-27 Current versionaffected

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43701 HIGH (7.1) 2026-06-29 Current versionaffected

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5.2
CVE-2026-43731 HIGH (8.8) 2026-06-29 Current versionaffected

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5.2
CVE-2026-43705 HIGH (8.8) 2026-06-29 Current versionaffected

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5.2
CVE-2026-43725 HIGH (7.1) 2026-06-29 Current versionaffected

The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5.2
CVE-2026-43735 HIGH (8.1) 2026-06-29 Current versionaffected

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5.2
CVE-2026-43715 HIGH (8.8) 2026-06-29 Current versionaffected

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5.2
CVE-2026-28907 HIGH (8.1) 2026-05-11 Current versionaffected

The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28947 HIGH (8.8) 2026-05-11 Current versionaffected

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-43658 HIGH (7.5) 2026-05-11 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28905 HIGH (7.5) 2026-05-11 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28913 HIGH (7.5) 2026-05-11 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28944 HIGH (7.5) 2026-05-11 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28883 HIGH (7.5) 2026-05-11 Current versionaffected

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-43660 HIGH (7.5) 2026-05-11 Current versionaffected

A validation issue was addressed with improved logic. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28904 HIGH (7.5) 2026-05-11 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28953 HIGH (7.5) 2026-05-11 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28962 HIGH (7.5) 2026-05-11 Current versionaffected

This issue was addressed with improved access restrictions. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may disclose sensitive user information.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28847 HIGH (8.8) 2026-05-11 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28955 HIGH (8.8) 2026-05-11 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-20652 HIGH (7.5) 2026-02-11 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A remote attacker may be able to cause a denial-of-service.

Affected versions
  • From (including) 0 - Up to (excluding) 26.3
CVE-2025-43529 HIGH (8.8) 2025-12-17 Current versionaffected

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.

Affected versions
  • From (including) 0 - Up to (excluding) 26.2
CVE-2025-43526 CRITICAL (9.8) 2025-12-17 Current versionaffected

This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted.

Affected versions
  • From (including) 0 - Up to (excluding) 26.2
CVE-2025-43502 HIGH (7.5) 2025-11-04 Current versionaffected

A privacy issue was addressed by removing sensitive data. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. An app may be able to bypass certain Privacy preferences.

Affected versions
  • From (including) 0 - Up to (excluding) 26.1
CVE-2025-43431 HIGH (8.8) 2025-11-04 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to memory corruption.

Affected versions
  • From (including) 0 - Up to (excluding) 26.1
CVE-2025-43480 HIGH (8.1) 2025-11-04 Current versionaffected

The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious website may exfiltrate data cross-origin.

Affected versions
  • From (including) 0 - Up to (excluding) 26.1
CVE-2025-43376 HIGH (7.5) 2025-11-04 Current versionaffected

A logic issue was addressed with improved state management. This issue is fixed in Safari 26, iOS 18.7.7 and iPadOS 18.7.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. A remote attacker may be able to view leaked DNS queries with Private Relay turned on.

Affected versions
  • From (including) 0 - Up to (excluding) 26
CVE-2025-43419 HIGH (8.8) 2025-11-04 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to memory corruption.

Affected versions
  • From (including) 0 - Up to (excluding) 26
CVE-2025-43433 HIGH (8.8) 2025-11-04 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to memory corruption.

Affected versions
  • From (including) 0 - Up to (excluding) 26.1
CVE-2025-43343 CRITICAL (9.8) 2025-09-15 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26
CVE-2025-43342 CRITICAL (9.8) 2025-09-15 Current versionaffected

A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26