Apple fixes 22 security flaws with Safari 26.6.1 update

Safari 26.3 Released With Vision Pro Fullscreen Upgrade and Zstandard Support

Apple has detailed the security content of Safari 26.6.1, confirming that the latest browser update fixes 22 WebKit vulnerabilities affecting Macs running macOS Sonoma and macOS Sequoia.

The update arrived on August 18 alongside Apple’s latest round of security-focused software releases, and several of the fixed issues involved memory handling, crashes, use-after-free bugs, and other problems triggered by maliciously crafted web content.

Safari 26.6.1 fixes 22 WebKit vulnerabilities

Apple says two of the vulnerabilities could allow malicious web content to cause memory corruption, while several others could trigger Safari crashes or unexpected process termination. The company also fixed a WebKit History issue where visiting a specially crafted website could expose sensitive data.

Don’t miss the best of The Mac Observer

Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.

Or get it by email

The update addresses the flaws through improved bounds checking, memory handling, input validation, locking, state management, and other WebKit security changes.

OpenAI Codex Security appears nine times in Apple’s CVE credits for Safari 26.6.1, with Amy Burnett named alongside the system. Other credited researchers include Henock Habte, Shubham Chaskar, Josef Korbel, Cisco Talos researchers, and TrendAI Zero Day Initiative.

Safari 26.6.1 is available for macOS Sonoma and macOS Sequoia, and users can install the update through Software Update to receive the latest WebKit security fixes.

Discussion

Join the discussionCommenting as a guest — your email is never published · Log in

Protected by Akismet — be kind, stay on topic.

This site uses Akismet to reduce spam. Learn how your comment data is processed.