Impact
Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS contain a memory handling flaw that may be triggered when processing maliciously crafted web content. The bug is a classic out‑of‑bounds write (CWE‑119) that can corrupt data structures and cause the affected process to terminate unexpectedly, resulting in a denial‑of‑service condition for the user.
Affected Systems
Affected Apple products include Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue is addressed in Safari 26.1, iOS 18.7.2 and 26.1, iPadOS 18.7.2 and 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, and watchOS 26.1.
Risk and Exploitability
The CVSS score of 4.3 reflects moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widely used exploits are documented. The likely attack vector is remote: an attacker who can supply malicious web content that a user or application renders can trigger the memory handling flaw, causing a crash and denying service to the affected device. No elevated privileges or additional prerequisites are required; any user capable of displaying vulnerable content could potentially trigger the failure.
OpenCVE Enrichment