Description
A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Published: 2025-07-29
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Crash-based Denial of Service
Action: Patch
AI Analysis

Impact

A logic flaw in Apple Safari and macOS allows maliciously crafted web content to trigger an unexpected crash, resulting in a denial of service that impacts the user session and application stability. The issue leads to a controlled failure rather than arbitrary code execution, but it can be leveraged by attackers to disrupt user experience and potentially interrupt critical services that rely on Safari. The vulnerability is identified as CWE‑703, indicating an insecure implementation of logic checks.

Affected Systems

Apple Safari browsers older than version 18.6 and macOS releases before Sequoia 15.6 are susceptible. The update to Safari 18.6 and macOS Sequoia 15.6 contains the necessary logic fixes that prevent the crash.

Risk and Exploitability

The CVSS score of 6.5 assigns this flaw a moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. Apple has not listed this vulnerability in the CISA KEV catalog, indicating no known public exploitation. Attackers would most likely need to entice users to visit a crafted webpage or deliver malicious HTML, so the primary attack vector is remote via the internet. Successful exploitation results in application termination and a brief treatment of denial of service rather than a compromise of the operating system.

Generated by OpenCVE AI on April 28, 2026 at 00:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Safari to version 18.6 or later.
  • Upgrade macOS to Sequoia 15.6 or a newer release that includes the logic fix.
  • If an update is not yet available, restrict browsing of untrusted content or use content filters to block potentially malicious web pages.

Generated by OpenCVE AI on April 28, 2026 at 00:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-23062 A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
History

Mon, 03 Nov 2025 20:30:00 +0000


Thu, 31 Jul 2025 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Thu, 31 Jul 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Apple safari
Apple sequoia
Vendors & Products Apple
Apple macos
Apple safari
Apple sequoia

Wed, 30 Jul 2025 23:15:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Wed, 30 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Jul 2025 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-703
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Tue, 29 Jul 2025 23:45:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:27:22.115Z

Reserved: 2025-01-17T00:00:44.996Z

Link: CVE-2025-24188

cve-icon Vulnrichment

Updated: 2025-11-03T19:43:38.751Z

cve-icon NVD

Status : Modified

Published: 2025-07-30T00:15:30.053

Modified: 2025-11-03T20:17:50.200

Link: CVE-2025-24188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T00:45:17Z

Weaknesses