Impact
The vulnerability in WebKitGTK can lead to a denial‑of‑service when a browser processes specially crafted web content. Based on the description, it is inferred that a flaw in memory handling may allow an attacker to exhaust system memory, causing the application to become unresponsive or crash. The weakness corresponds to CWE‑770, indicating a problem with memory allocation that can result in resource exhaustion.
Affected Systems
Apple’s WebKit‑based browsers and operating systems are affected. Notable impacted products include Safari, Safari on iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Fixed releases are Safari 18.6, iOS 18.6, iPadOS 18.6 and 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, and watchOS 11.6.
Risk and Exploitability
The CVSS score of 6.2 indicates a moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not currently listed in CISA’s KEV catalog. An attacker would need to deliver malicious web content to a vulnerable WebKitGTK instance, likely through a user‑initiated action such as visiting a compromised website; Based on the description, it is inferred that this could trigger memory exhaustion and force the browser to crash.
OpenCVE Enrichment
Debian DLA
Debian DSA
EUVD
Ubuntu USN