Impact
Processing maliciously crafted web content can cause an unexpected crash in the WebKit-based browser process, resulting in denial of service to the affected user. This vulnerability is caused by improper input validation in the rendering engine, which is cataloged as CWE-79. The crash does not lead directly to code execution, but it can disrupt user access to web content and may be combined with other vulnerabilities in higher-privilege processes.
Affected Systems
Affected Apple products include Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue is mitigated by upgrading to version 26.1 or later on all these platforms, which contains improved checks that prevent the crash.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate level of severity, while the EPSS score of less than 1% shows a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog, so no known active exploits are reported. The attack vector is inferred to be web content accessed by a user, such as a malicious URL or embedded media, because the issue is triggered by rendering specially prepared data.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN