Impact
The vulnerability comes from a flaw in memory handling that can cause a process crash when maliciously crafted web content is processed. The issue is resolved by improved memory handling, with a fix in Safari 26.5, iOS 18.7.9 / 26.5, iPadOS 18.7.9 / 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5. The crash produces a temporary denial of service: the affected application or operating system may become unresponsive or relaunch. There is no indication that the crash can be used for code execution or privilege escalation.
Affected Systems
Apple Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS are affected. The fix is delivered in Safari 26.5, iOS 18.7.9 and 26.5, iPadOS 18.7.9 and 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity impact. The EPSS score of less than 1 % and the absence from CISA’s KEV catalog suggest that no publicly confirmed exploits exist as of the latest data. The likely attack vector is the delivery of malicious web content, which is inferred from the description but not explicitly detailed; the precise method of delivery (browser, embedded web view, or other renderer) is not specified. Provided that the bug does not grant code execution, the risk remains limited to denial of service until an exploit that converts the crash into a more severe attack emerges.
OpenCVE Enrichment