Impact
A memory handling flaw in WebKitGTK allows maliciously crafted web content to cause Safari or related Apple browsers to crash. The vulnerability is categorized as a buffer overread or write (CWE-119 and CWE-120). The crash results in a denial of service to the user, potentially interrupting web browsing or app functionality, but no remote code execution is reported.
Affected Systems
Apple Safari, iOS, iPadOS, macOS Sequoia, tvOS, visionOS, and watchOS are affected. The issue is fixed in Safari 18.6, iOS 18.6, iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, and watchOS 11.6; all earlier versions of these products are vulnerable.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity. The EPSS score is below 1%, implying a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker delivering malicious web content that the browser renders, leading to a crash. The exploit requires user interaction (visiting a page) and does not grant elevated privileges or data compromise, but it can be used as a disruptive denial of service attack.
OpenCVE Enrichment
Debian DLA
Debian DSA
EUVD
Ubuntu USN