Impact
A flaw in URL validation allows processing of maliciously crafted web content to trigger unexpected redirection. The weakness maps to CWE‑863 and can lead to users being steered to attacker-controlled sites, potentially exposing sensitive information or facilitating further attacks. The impact is an unauthorized change in navigation, compromising user intent and increasing the risk of phishing or malware delivery.
Affected Systems
Apple Safari and the iOS and iPadOS operating systems are affected. The vulnerability is present in all releases of Safari, iOS, and iPadOS before version 26. It is fixed in Safari 26, iOS 26, and iPadOS 26.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. EPSS indicates a very low exploitation probability (less than 1 %). The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is delivery of malicious web content that a user may view, likely from a compromised or malicious website or email attachment. Exploitation would require the user to open or interact with the crafted content.
OpenCVE Enrichment
EUVD