ZDI-26-610: Apple Safari JavaScriptCore B3 ReduceStrength Phase Use-After-Free RCE Vulnerability
Executive Summary
A use‑after‑free flaw in Safari’s JavaScriptCore (B3 ReduceStrength phase) lets remote attackers run arbitrary code on affected Apple Safari installations. Exploitation requires user interaction, such as visiting a malicious web page or opening a malicious file. The vulnerability has a CVSS score of 8.8 and is assigned CVE‑2026‑64715.
Intelligence Metadata - Source Publisher: Zero Day Initiative - Published Date: 2026-08-24T05:00:00+00:00 - Category: cves
Original Description: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-64715.
"In separateness lies the world's great misery, in compassion lies the world's true strength."
— Buddha