Impact
Improper state management in the WebKitGTK engine causes it to crash when processing specially crafted web content. This results in a denial of service, potentially disrupting user sessions and compromising the availability of browsers or web‑based applications. The weakness involves improper input validation (CWE‑20) and logical errors in state handling (CWE‑703).
Affected Systems
The bug affects Apple products, including Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS on versions before 26.1. The issue is present in all current releases of these platforms that have not applied the 26.1 update, which incorporates the necessary state‑management fix.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity impact, and the EPSS score of <1% shows a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers can provoke the crash by delivering malicious web content within a page that a user visits, leading to a local denial of service. The low exploitation likelihood reflects the lack of readily available exploit code and the requirement for the target to load the affected web content.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN