Impact
The flaw occurs when Apple’s WebKitGTK engine processes maliciously crafted web content, leading to memory corruption. The weakness is identified as CWE‑119, representing an improper handling of buffer boundaries. While the data does not provide a concrete exploitation example, the nature of the buffer overflow implies potential to execute code, thereby threatening confidentiality, integrity, and availability.
Affected Systems
Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The vulnerability exists in all releases before version 26 of each product and has been corrected in Safari 26, iOS 26, iPadOS 26, macOS 26, tvOS 26, visionOS 26, and watchOS 26.
Risk and Exploitability
The CVSS score of 8.8 denotes a high severity. The EPSS score of less than 1 % indicates a low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV. The attack vector can be inferred as remote via malicious web content, given the memory corruption in a browser engine.
OpenCVE Enrichment