Impact
The vulnerability is a type confusion flaw in WebKitGTK that can cause Safari to crash when it processes specially crafted web content. This type confusion, catalogued as CWE‑843, means that the application interprets data of one type as another, leading to an unhandled exception. The crash removes service availability for the user, potentially resulting in a denial of service. No arbitrary code execution or information disclosure is reported in the description, so the primary risk is service interruption.
Affected Systems
Apple products with Safari and other web browsers on iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The flaw persists in releases before Safari 18.5, iOS 18.5, iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, and watchOS 11.5. The vulnerability is also present in WebKitGTK deployments on Red‑Hat Enterprise Linux 8, 9, and several RHEL 8.x and RHEL 9.x builds. Users on any of these operating systems running Safari or WebKitGTK should be aware that malicious pages could trigger a crash.
Risk and Exploitability
The CVSS score of 4.3 classifies the flaw as moderate, and the EPSS score of 1 % indicates a low likelihood of widespread exploitation. Because the issue only manifests when maliciously crafted content is rendered, the attack vector is effectively local to the user’s browser session or a phishing page. The vulnerability is not listed in the CISA KEV catalog, so no known field‑operational exploitation has been reported.
OpenCVE Enrichment
Debian DLA
Debian DSA
EUVD
Ubuntu USN