Impact
The flaw is a memory handling error (CWE-119) that can be triggered when WebKitGTK processes maliciously crafted web content. This results in a deterministic crash of Safari and the system’s WebKit-based applications, causing a denial‑of‑service condition for the user session but not enabling code execution or data exfiltration.
Affected Systems
Affecting Apple’s Safari browser and the underlying WebKit engine across all major Apple platforms—iOS, iPadOS, macOS, visionOS, and watchOS. The vulnerability is resolved in Safari 26, iOS 26, iPadOS 26, macOS Tahoe 26, visionOS 26, and watchOS 26, as documented by Apple’s update support pages.
Risk and Exploitability
With a CVSS score of 6.5 it is considered moderate severity, while an EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog, suggesting no known active exploitation. The likely attack vector involves a maliciously crafted webpage or data stream delivered to the user’s browser; the attacker needs only to supply the bad content and does not require elevated privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA
EUVD
Ubuntu USN