Impact
A use‑after‑free bug in WebKitGTK’s memory management allows an attacker to crash a process that parses malicious web content. The flaw can cause the application or system process to terminate unexpectedly, resulting in a denial of service and a service interruption for the user. The vulnerability is classified as CWE‑416, a memory management error that can lead to unstable execution.
Affected Systems
Apple products including Safari, iOS, iPadOS, macOS, visionOS, and watchOS are affected. Versions prior to Safari 26.2, iOS 18.7.2 and iPadOS 18.7.2, macOS 26.2, visionOS 26.2, and watchOS 26.2 contain the issue and have not applied the fix announced by Apple.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation, and it is not listed in CISA’s KEV catalog. The vulnerability is likely to be exploited remotely through crafted web content or embedded web views, as the flaw is triggered when malicious data is processed by the web engine. In the absence of known active exploits, the risk remains primarily theoretical but should be addressed promptly to prevent potential denial‑of‑service attacks.
OpenCVE Enrichment
Debian DLA
Debian DSA