Impact
An issue with memory handling in WebKitGTK allows processing of maliciously crafted web content to trigger an unexpected process crash. The flaw is a buffer overflow or out-of-bounds write (CWE-120 and CWE-787), leading to a denial of service when the browser renders the content.
Affected Systems
Apple Safari running on macOS, iOS, iPadOS and visionOS is affected. Versions prior to Safari 26.4, iOS 26.4, iPadOS 26.4, macOS Tahoe 26.4, and visionOS 26.4 contain vulnerable code. Update to the respective 26.4 releases to obtain the patch.
Risk and Exploitability
The CVSS base score of 4.3 indicates moderate severity, but the EPSS score below 1% and absence from CISA's KEV catalog suggest a low likelihood of exploitation. Attackers would need to craft malicious web content and deliver it to a user’s browser. The impact is primarily availability, as the crash causes a denial of service but does not compromise confidentiality or integrity.
OpenCVE Enrichment