Impact
Processing maliciously crafted web content may lead to an unexpected process crash due to improper input validation (CWE-20) and null pointer dereference (CWE-476). If an attacker can supply the crafted content, the affected process will terminate, potentially causing unavailability of the web application or browser and disrupting user experience.
Affected Systems
Apple products including Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The fix is applied in Safari 18.5, iOS 18.5, iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, and watchOS 11.5. Red Hat Enterprise Linux 8 and 9 families may also be impacted through WebKitGTK updates.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of 1% shows a low likelihood of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is a malicious web page that renders content in a WebKitGTK-enabled application, which an attacker can use to cause a crash.
OpenCVE Enrichment
Debian DLA
Debian DSA
EUVD
Ubuntu USN