Impact
The flaw is a memory handling error that lets a malicious website process data that should be confined to the browser sandbox. The vulnerability is rooted in several classic memory errors such as buffer overreads, use‑after‑free, and buffer overflows, all of which are reflected in the assigned CWEs. If triggered, an attacker could read or alter content that is normally protected, enabling the site to access restricted information or influence sandboxed operations.
Affected Systems
Apple Safari on macOS, iOS, iPadOS, tvOS, visionOS and watchOS is affected whenever the software version is older than the 26.4 releases. The fix is delivered in Safari 26.4, iOS 26.4, iPadOS 26.4, macOS 26.4, tvOS 26.4, visionOS 26.4 and watchOS 26.4.
Risk and Exploitability
The CVSS score of 4.3 places this vulnerability in the low severity range, and the EPSS score of less than 1 % indicates that practical exploitation is unlikely at present. It is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is inferred to be remote, originating from a specially crafted web page that a user visits in Safari, exploiting the memory handling flaw to escape the sandbox. No active exploits or publicly available proof‑of‑concept code have been reported.
OpenCVE Enrichment