Skip to content
AppleCVE-2026-64728

Apple Safari: protection mechanism failure

Medium6.5CVE-2026-64728 · Published Jul 27, 2026 · updated Jul 28, 2026

A permissions issue was addressed with improved validation. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Maliciously crafted web content may violate iframe sandboxing policy.

Apple advisory

Affected versions

PackageAffectedFixed in
Safari
Product
< 26.626.6
iOS and iPadOS
Product
< 26.626.6
macOS
Product
< 26.626.6
tvOS
Product
< 26.626.6
visionOS
Product
< 26.626.6
watchOS
Product
< 26.626.6
Details and references

More Apple advisories

All Apple
Advisory
Apple iOS and iPadOS: out-of-bounds write
Critical9.8Jul 27
Apple iOS and iPadOS: out-of-bounds write
Critical9.8Jul 27
Apple iOS and iPadOS: buffer overflow
Critical9.8Jul 27
Apple iOS and iPadOS: out-of-bounds write
Critical9.8Jul 27
Apple iOS and iPadOS: integer overflow
Critical9.8Jul 27
A memory initialization issue was addressed with improved memory handling
Critical9.8Jul 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.