CVE-2026-20652High· 7.5▾ TwilightThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A remote attacker may be able to cause a denial-of-service.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
0.6% → 0.6%
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A remote attacker may be able to cause a denial-of-service.
safari < 26.3ipados < 18.7.5ipados >= 26.0, < 26.3iphone_os < 18.7.5iphone_os >= 26.0, < 26.3macos < 26.3visionos < 26.3Upgrade past the affected range:
safari 26.3ipados 26.3iphone_os 26.3macos 26.3visionos 26.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-20644Medium· 6.5The issue was addressed with improved memory handling
CVE-2026-20636Medium· 6.5The issue was addressed with improved memory handling
CVE-2026-20635Medium· 4.3The issue was addressed with improved memory handling
CVE-2026-20608Medium· 5.5This issue was addressed through improved state management
CVE-2025-43214Medium· 6.5The issue was addressed with improved memory handling
CVE-2025-43213Medium· 6.5The issue was addressed with improved memory handling