Impact
The vulnerability is a memory handling flaw that can trigger a local crash when a crafted WebKit page is loaded. The flaw is a buffer overflow and a resource exhaustion weakness, meaning a remote attacker can cause the browser to crash or consume excessive resources. As a result, a remote user can cause a denial‑of‑service on the affected device, impacting availability significantly.
Affected Systems
Affected Apple products include Safari, iOS, iPadOS, macOS, and visionOS. Specifically Safari 26.3, iOS 18.7.5 and 26.3, iPadOS 18.7.5 and 26.3, macOS Tahoe 26.3, and visionOS 26.3 are susceptible.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high impact, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely client‑side, requiring an attacker to lure a user into visiting malicious WebKit content. If exploited, the browser or related system component will crash or become unresponsive, leading to service interruption. Given the high severity and potential for service disruption, organizations should prioritize applying the available updates.
OpenCVE Enrichment
Debian DLA
Debian DSA