NCSC-2026-0317 [1.00] [M/H] Vulnerabilities resolved in Apple macOS
Apple has resolved vulnerabilities in macOS Tahoe 26.6.2. The vulnerabilities involve multiple aspects of memory management, input validation and state management within Apple's operating systems and Safari browser. A number of vulnerabilities allow a malicious actor to cause memory corruption by processing specially crafted web content or images, which can lead to unexpected crashes, system termination or leaking of sensitive user information. Other vulnerabilities involve use-after-free conditions and out-of-bounds memory access, which can also result in system instability or exposure of kernel memory. The problems exist in the mechanisms that control app access to user data, the processing of web content and the handling of images. By applying improved validation, memory management and locking mechanisms, Apple prevents these vulnerabilities from being exploited to cause crashes, denial-of-service or unauthorized information exposure.
CSIRTS triage
- What
- Multiple memory management and validation flaws including use-after-free, out-of-bounds access, and memory corruption triggered by malicious web content or images.
- Who is affected
- macOS Tahoe 26.6.2 users and systems processing untrusted web content or images.
- Urgency
- High priority; vulnerabilities lead to unexpected crashes, kernel memory leaks, and potential denial of service.
- Action
- Update macOS to the patched version addressing CVE-2026-65339, CVE-2026-65347, CVE-2026-65346, CVE-2026-64788, CVE-2026-65343, CVE-2026-65349, CVE-2026-65330, and CVE-2026-64784.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch macOS
Get an email when a new macOS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0317
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-653390.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-653470.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-653460.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647880.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-653430.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-653490.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-653300.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647840.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-437950.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-653380.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] WebKitGTK: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Apple macOS, iOS and iPadOS: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0319 [1.00] [M/H] Vulnerabilities resolved in Apple iOS and iPadOSncsc-nl
- unknownApple Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Apple products (August 18, 2026)cert-fr-avis
- mediumCVE-2026-65351: This issue was addressed through improved state management. This issue is fixed in Safari 26.6…nvd
- mediumCVE-2026-65349: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS…nvd
- mediumCVE-2026-65347: The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.…nvd
- highCVE-2026-65346: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 2…nvd
- highCVE-2026-65343: A use after free issue was addressed with improved memory management. This issue is fixed in i…nvd
- mediumCVE-2026-65341: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, i…nvd
- mediumCVE-2026-65340: This issue was addressed through improved state management. This issue is fixed in Safari 26.6…nvd
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21