Apple has detailed the security content of Safari 26.6.1, confirming that the latest browser update fixes 22 WebKit vulnerabilities affecting Macs running macOS Sonoma and macOS Sequoia.
The update arrived on August 18 alongside Apple’s latest round of security-focused software releases, and several of the fixed issues involved memory handling, crashes, use-after-free bugs, and other problems triggered by maliciously crafted web content.
Safari 26.6.1 fixes 22 WebKit vulnerabilities
Apple says two of the vulnerabilities could allow malicious web content to cause memory corruption, while several others could trigger Safari crashes or unexpected process termination. The company also fixed a WebKit History issue where visiting a specially crafted website could expose sensitive data.
Don’t miss the best of The Mac Observer
Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.
The update addresses the flaws through improved bounds checking, memory handling, input validation, locking, state management, and other WebKit security changes.
OpenAI Codex Security appears nine times in Apple’s CVE credits for Safari 26.6.1, with Amy Burnett named alongside the system. Other credited researchers include Henock Habte, Shubham Chaskar, Josef Korbel, Cisco Talos researchers, and TrendAI Zero Day Initiative.
Safari 26.6.1 is available for macOS Sonoma and macOS Sequoia, and users can install the update through Software Update to receive the latest WebKit security fixes.
Discussion