Impact
The vulnerability in WebKitGTK arises from improper memory handling that can cause an unexpected crash of Safari when processing maliciously crafted web content. The flaw leads to a browser interruption without leaking data or executing arbitrary code, so the primary impact is a denial of service to the end user.
Affected Systems
Apple’s Safari, iOS 18.5, iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, and watchOS 11.5 are all affected. The issue also applies to Linux distributions that rely on the WebKitGTK component, such as Red Hat Enterprise Linux 8, 8.4, 8.6, 8.8, 9.0, 9.2, and their Extended Support releases.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, and the EPSS score of less than 1 % suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would need to deliver specially crafted web content to a vulnerable user’s browser, which could be achieved via malicious webpages, phishing links, or compromised websites. The crash could temporarily render Safari unusable but does not compromise system integrity or data confidentiality.
OpenCVE Enrichment
Debian DLA
Debian DSA
EUVD
Ubuntu USN