Impact
The flaw is a use‑after‑free bug in WebKitGTK that can be triggered by malicious web content. When triggered, the renderer process crashes, resulting in a denial of service to the user. The vulnerability does not allow code execution or data compromise, limiting its impact to service interruption.
Affected Systems
Apple Safari, iOS, iPadOS, and macOS are affected. Vulnerable releases include Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, the iOS 26.2 and iPadOS 26.2 releases, and macOS Tahoe 26.2. Devices running earlier versions remain exposed.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to deliver crafted web content—most likely through remote web pages or local files—to trigger the crash. The attack vector is inferred to be remote or local content delivery, but no privilege escalation or data exfiltration is possible.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN