Impact
Improved state management in WebKitGTK failed to prevent a crash when processing maliciously crafted web content. The flaw causes the browser process to terminate unexpectedly, resulting in a denial of service. The weakness involves improper input validation and incorrect control flow, as identified by CWE-20 and CWE-703.
Affected Systems
All Apple browsers and web‑view components—Safari, iOS, iPadOS, macOS, tvOS, and visionOS—are affected through version 26.0. Apple recommends upgrading to version 26.1 or later to receive the state‑management fix that prevents the crash.
Risk and Exploitability
The CVSS score of 4.3 reflects a low severity event, and the EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker can trigger the defect by hosting or linking to specially crafted web content; the user’s act of navigating to the page is typically sufficient to cause the crash. Because no additional privileges are required, the primary threat is service disruption rather than data compromise or code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN