Impact
A memory handling issue in WebKitGTK can cause Safari to crash when rendering maliciously crafted web content. The flaw, associated with buffer overflow (CWE‑119) and improper error handling (CWE‑508), results in a denial‑of‑service scenario whereby the affected Safari process terminates unexpectedly. No code execution or data disclosure is reported, but the crash can disrupt user activity and potentially interrupt background tasks.
Affected Systems
Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The vulnerability is fixed in Safari 18.4, iOS 18.4, iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, and watchOS 11.4. Red Hat platform CPEs are listed but no specific Red Hat product impact is detailed in the advisory.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1 % shows a very low probability that attackers are actively exploiting the flaw at present. The vulnerability is not cataloged in CISA’s KEV list. Exploitation is likely achieved by delivering specially crafted web content, which could be embedded in malicious sites or emails. The attack surface is broad because any user who views the content can trigger the crash, but the lack of disclosed remote code execution limits the immediate threat.
OpenCVE Enrichment
Debian DLA
Debian DSA
EUVD
Ubuntu USN