CVE-2026-64718

Overview

Advisory: Apple Security Advisory

Impact:

Description: Processing maliciously crafted web content may lead to an unexpected Safari crash

Researchers: OGINOME Tomohito, an anonymous researcher

Attribute Value
CVE CVE-2026-64718
Bugzilla 313935
Component WebCore
Bug Class UAF
Severity medium
Commit 95f9f59bb141325d…
Advisory Apple Advisory

Root Cause Analysis

A use-after-free issue was addressed with improved memory management.

Files Changed

Source Files

  • Source/WebCore/platform/graphics/cg/PathCG.cpp

Test Files

  • LayoutTests/fast/canvas/offscreen-worker-unsafe-isPointInStroke-call-expected.txt
  • LayoutTests/fast/canvas/offscreen-worker-unsafe-isPointInStroke-call.html