Impact
Processing maliciously crafted web content may trigger a buffer overflow (CWE‑120) or an out‑of‑bounds write (CWE‑770), which causes the browser or related processes to crash. The consequence is a denial of service where the affected application session terminates, potentially interrupting the user’s browser or web‑based experience. No information indicates that the flaw allows data disclosure, persistence, or privilege escalation; the impact is confined to the crashing process.
Affected Systems
Apple Safari, Apple iOS, Apple iPadOS, Apple macOS, and Apple visionOS are affected. The vulnerable releases include Safari 26.3, iOS 18.7.5 and 26.3, iPadOS 18.7.5 and 26.3, macOS Tahoe 26.3, and visionOS 26.3.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% reflects a very low likelihood of exploitation as of the analysis time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to deliver malicious web content, typically through a compromised or malicious website, to trigger the crash by exploiting the browser’s processing engine.
OpenCVE Enrichment
Debian DLA
Debian DSA