{"slug": "safari-26-6-1-patches-multiple-webkit-security-flaws-on-macos-sonoma-and-sequoia", "title": "Safari 26.6.1 patches multiple WebKit security flaws on macOS Sonoma and Sequoia", "summary": "Apple released Safari 26.6.1 on August 18, 2026, for macOS Sonoma and macOS Sequoia, patching 22 WebKit security vulnerabilities, including two that could lead to memory corruption. OpenAI Codex Security is credited nine times in the CVE credits, highlighting the growing role of AI tools in finding security flaws in Apple's software.", "body_md": "Following yesterday’s [wave of point updates](https://9to5mac.com/2026/08/17/apple-releases-ios-26-6-1-for-iphone-heres-whats-new/) with security fixes, Apple has now detailed the security content of Safari 26.6.1. Here are the details.\n\n## Codex is listed multiple times in the CVE credits\n\nApple today updated its “Apple security releases” page with details about the bug fixes included in Safari 26.6.1, which is now available for macOS Sonoma and macOS Sequoia.\n\nAccording to the document, the update includes 22 CVEs, all related to WebKit, including two vulnerabilities in which “processing maliciously crafted web content [could] lead to memory corruption.”\n\nInterestingly, and in line with recent security updates, OpenAI Codex Security is listed nine times, [further highlighting](https://9to5mac.com/2026/07/27/claude-codex-and-other-ai-tools-credited-in-todays-apple-security-releases/) the growing role of AI tools in finding security vulnerabilities in Apple’s software.\n\nHere’s Apple’s full security content for Safari 26.6.1:\n\n## Safari 26.6.1\n\nReleased August 18, 2026\n\n## WebKit\n\nAvailable for: macOS Sonoma and macOS Sequoia\n\nImpact: Processing maliciously crafted web content may lead to an unexpected Safari crash\n\nDescription: An out-of-bounds access issue was addressed with improved bounds checking.\n\nWebKit Bugzilla: 317632\n\nCVE-2026-64784: Janggoon Lee of Out of Bounds, OpenAI Codex Security – Amy Burnett\n\n## WebKit\n\nAvailable for: macOS Sonoma and macOS Sequoia\n\nImpact: Processing maliciously crafted web content may lead to an unexpected Safari crash\n\nDescription: The issue was addressed with improved memory handling.\n\nWebKit Bugzilla: 313452\n\nCVE-2026-43795: wwwlk\n\nWebKit Bugzilla: 318348\n\nCVE-2026-65338: OpenAI Codex Security – Amy Burnett\n\n## WebKit\n\nAvailable for: macOS Sonoma and macOS Sequoia\n\nImpact: Processing maliciously crafted web content may lead to memory corruption\n\nDescription: The issue was addressed with improved memory handling.\n\nWebKit Bugzilla: 318405\n\nCVE-2026-65341: Henock Habte\n\n## WebKit\n\nAvailable for: macOS Sonoma and macOS Sequoia\n\nImpact: Processing maliciously crafted web content may lead to an unexpected Safari crash\n\nDescription: A memory corruption vulnerability was addressed with improved locking.\n\nWebKit Bugzilla: 321480\n\nCVE-2026-64782: Seonwook Kim, Shubham Chaskar, lattice, Josef Korbel\n\n## WebKit\n\nAvailable for: macOS Sonoma and macOS Sequoia\n\nImpact: Processing maliciously crafted web content may lead to an unexpected Safari crash\n\nDescription: The issue was addressed with improved input validation.\n\nWebKit Bugzilla: 321484\n\nCVE-2026-64781: Thomas Guillem\n\n## WebKit\n\nAvailable for: macOS Sonoma and macOS Sequoia\n\nImpact: Processing maliciously crafted web content may lead to an unexpected Safari crash\n\nDescription: This issue was addressed through improved state management.\n\nWebKit Bugzilla: 321517\n\nCVE-2026-65351: Niels Hofmans\n\nWebKit Bugzilla: 316996\n\nCVE-2026-65340: Claudio Bozzato and Francesco Benvenuto of Cisco Talos, Josef Korbel (Citadelo)\n\nWebKit Bugzilla: 317142\n\nCVE-2026-65337: OpenAI Codex Security – Amy Burnett\n\nWebKit Bugzilla: 317349\n\nCVE-2026-65336: Josef Korbel\n\nWebKit Bugzilla: 316723\n\nCVE-2026-65335: OpenAI Codex Security – Amy Burnett\n\nWebKit Bugzilla: 317603\n\nCVE-2026-65333: OpenAI Codex Security – Amy Burnett\n\nWebKit Bugzilla: 317450\n\nCVE-2026-65332: OpenAI Codex Security – Amy Burnett\n\nWebKit Bugzilla: 317611\n\nCVE-2026-65331: OpenAI Codex Security – Amy Burnett\n\n## WebKit\n\nAvailable for: macOS Sonoma and macOS Sequoia\n\nImpact: Processing maliciously crafted web content may lead to an unexpected process crash\n\nDescription: A use-after-free issue was addressed with improved memory management.\n\nWebKit Bugzilla: 316347\n\nCVE-2026-64715: Hossein Lotfi (@hosselot) of TrendAI Zero Day Initiative\n\n## WebKit\n\nAvailable for: macOS Sonoma and macOS Sequoia\n\nImpact: Processing maliciously crafted web content may lead to an unexpected Safari crash\n\nDescription: The issue was addressed with improved checks.\n\nWebKit Bugzilla: 316918\n\nCVE-2026-64780: OpenAI Codex Security – Amy Burnett\n\n## WebKit\n\nAvailable for: macOS Sonoma and macOS Sequoia\n\nImpact: Processing maliciously crafted web content may lead to an unexpected Safari crash\n\nDescription: A memory corruption issue was addressed with improved state management.\n\nWebKit Bugzilla: 316791\n\nCVE-2026-65334: OpenAI Codex Security – Amy Burnett\n\n## WebKit\n\nAvailable for: macOS Sonoma and macOS Sequoia\n\nImpact: Processing maliciously crafted web content may lead to memory corruption\n\nDescription: A memory corruption issue was addressed with improved memory handling.\n\nWebKit Bugzilla: 317317\n\nCVE-2026-43794: Dung Do (@_piers2) of Calif.io\n\n## WebKit\n\nAvailable for: macOS Sonoma and macOS Sequoia\n\nImpact: Processing maliciously crafted web content may lead to an unexpected process termination\n\nDescription: A use-after-free issue was addressed with improved memory management.\n\nWebKit Bugzilla: 313703\n\nCVE-2026-64787: 杉山 壮太, Shubham Chaskar\n\n## WebKit History\n\nAvailable for: macOS Sonoma and macOS Sequoia\n\nImpact: Visiting a maliciously crafted website may leak sensitive data\n\nDescription: The issue was addressed with improved checks.\n\nWebKit Bugzilla: 315528\n\nCVE-2026-64778: Mohit Negi\n\n## WebKit Storage\n\nAvailable for: macOS Sonoma and macOS Sequoia\n\nImpact: Processing maliciously crafted web content may lead to an unexpected Safari crash\n\nDescription: A memory corruption vulnerability was addressed with improved locking.\n\nWebKit Bugzilla: 321485\n\nCVE-2026-64779: Shubham Chaskar, Tommy DeVoss from Braze Security Team (@thedawgyg)\n\n## Additional recognition\n\n## WebKit\n\nWe would like to acknowledge Henock Habte for their assistance.\n\nTo learn more about Apple’s security releases, [follow this link](https://support.apple.com/en-us/100100).\n\n#### Worth checking out on Amazon\n\n[Geoffrey Cain – ‘Steve Jobs in Exile’](https://amzn.to/4v3CS5Q)[David Pogue – ’Apple: The First 50 Years’](https://amzn.to/46Y3nQj)[MacBook Neo](https://amzn.to/47vJmkn)[Logitech MX Master 4](https://amzn.to/3KmIQN7)[AirPods Pro 3](https://www.amazon.com/Apple-Cancellation-Translation-Headphones-High-Fidelity/dp/B0FQFB8FMG?tag=marcmendes-20)[AirTag (2nd Generation) – 4 Pack](https://amzn.to/4sewc3a)[Apple Watch Series 11](https://amzn.to/46VomDB)[Wireless CarPlay adapter](https://www.amazon.com/gp/product/B0F6T6N2B1?tag=marcmendes-20)\n\n*FTC: We use income earning auto affiliate links.* [More.](https://9to5mac.com/about/#affiliate)\n\n[our homepage](http://9to5mac.com/)for all the latest news, and follow 9to5Mac on\n\n[exclusive stories](https://9to5mac.com/feature/exclusive/),\n\n[reviews](https://9to5mac.com/guides/review/),\n\n[how-tos](https://9to5mac.com/guides/how-to/), and\n\n[subscribe to our YouTube channel](https://www.youtube.com/9to5mac)", "url": "https://wpnews.pro/news/safari-26-6-1-patches-multiple-webkit-security-flaws-on-macos-sonoma-and-sequoia", "canonical_source": "https://9to5mac.com/2026/08/18/safari-26-6-1-patches-multiple-webkit-security-flaws-on-macos-sonoma-and-sequoia/", "published_at": "2026-08-18 18:29:25+00:00", "updated_at": "2026-08-18 18:41:22.562967+00:00", "lang": "en", "topics": ["ai-tools", "ai-research"], "entities": ["Apple", "Safari 26.6.1", "WebKit", "OpenAI Codex Security", "Amy Burnett", "Cisco Talos", "TrendAI Zero Day Initiative"], "alternates": {"html": "https://wpnews.pro/news/safari-26-6-1-patches-multiple-webkit-security-flaws-on-macos-sonoma-and-sequoia", "markdown": "https://wpnews.pro/news/safari-26-6-1-patches-multiple-webkit-security-flaws-on-macos-sonoma-and-sequoia.md", "text": "https://wpnews.pro/news/safari-26-6-1-patches-multiple-webkit-security-flaws-on-macos-sonoma-and-sequoia.txt", "jsonld": "https://wpnews.pro/news/safari-26-6-1-patches-multiple-webkit-security-flaws-on-macos-sonoma-and-sequoia.jsonld"}}