Impact
A correctness issue in the rendering engine can cause a process to crash when handling maliciously crafted web content. The flaw is identified as an input validation weakness (CWE-20). Because the crash stops the affected process, the main consequence is interruption of service rather than disclosure of sensitive data or code execution.
Affected Systems
The vulnerability affects Apple’s Safari web browser across multiple platforms including macOS, iOS, iPadOS, tvOS, visionOS, and watchOS. The corrective updates are Safari 26 and equivalent OS releases such as iOS 18.7, 26, iPadOS 18.7, 26, macOS Tahoe 26, tvOS 26, visionOS 26, and watchOS 26. Any older version remaining on user devices remains vulnerable.
Risk and Exploitability
The CVSS score of 9.8 reflects a severe impact. The EPSS score of less than 1% indicates that the likelihood of real-world exploitation is currently very low, and the flaw is not listed in the CISA KEV catalog. Attackers would exploit the weakness by delivering specially crafted web content to a user’s browser, causing a crash without needing to exploit memory corruption or privileges. The impact is limited to denial of service for the user of the affected process, but it can be leveraged to disrupt user experience or to serve as a precursor to more targeted attacks if combined with other vulnerabilities.
OpenCVE Enrichment
Debian DLA
Debian DSA
EUVD
Ubuntu USN