Impact
A flaw in WebKitGTK’s state management allows maliciously crafted web content to trigger an unexpected process crash. The resulting denial of service can suspend the browsing process, disrupting user interactions without compromising system integrity or confidentiality.
Affected Systems
Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The vulnerability exists in versions up to Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, and watchOS 26.1.
Risk and Exploitability
The CVSS score is 4.3, reflecting a moderate impact. The EPSS value is below 1 %, indicating a low probability of exploitation at this time, and it is not listed in the CISA KEV catalog. The attack vector appears to be remote via malicious web content delivered to the user; no local privilege escalation or data theft is described.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN