Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Use‑After‑Free RCE in Apple Safari (CVE‑2026‑64715) Threatens Web Users

Apple Safari’s JavaScriptCore contains a use‑after‑free flaw (CVE‑2026‑64715) that lets remote attackers execute code when a user visits a malicious page, scoring 8.8 CVSS. Organizations must patch browsers promptly to satisfy SOC 2 change‑management and endpoint‑security controls.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
zerodayinitiative.com

Critical Use‑After‑Free RCE in Apple Safari (CVE‑2026‑64715) Threatens Web Users

What It Is — Apple Safari’s JavaScriptCore engine contains a use‑after‑free flaw in the B3 ReduceStrength phase. The bug allows a remote attacker to execute arbitrary code in the renderer process when a victim visits a malicious web page or opens a crafted file.

Exploitability — The vulnerability requires user interaction but can be weaponized with a simple malicious link; a proof‑of‑concept has been disclosed. CVSS 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates a high likelihood of successful exploitation.

Affected Products — Apple Safari (all versions prior to the August 2026 security update).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Change Management (CC6.1) and System Operations controls demand timely patching of client‑side software; unpatched browsers constitute a control gap.
  • Continuous evidence of patch deployment is required to demonstrate due diligence during a SOC 2 audit.
  • A successful exploit could compromise data confidentiality and integrity, jeopardizing the organization’s trust posture and audit defensibility.

Recommended Actions

  • Deploy Apple’s August 2026 Safari security update to every endpoint immediately.
  • Verify patch rollout with your endpoint‑management solution and retain logs as audit evidence.
  • Update your SOC 2 asset inventory to reflect the patched version and map the change to the relevant control.
  • Enforce browser‑hardening policies (e.g., block outdated versions, enable site isolation).

Source: Zero Day Initiative – ZDI‑26‑610 (CVE‑2026‑64715)

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-610/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →