Impact
Apple’s operating systems have a flaw where maliciously crafted web content can trigger improper memory handling, causing an unexpected process crash. The weakness does not allow code execution or data theft; it results in a denial‑of‑service scenario by destabilizing the affected process. The vulnerability is rooted in a buffer or memory access violation, aligning with CWE‑119 weaknesses.
Affected Systems
The issue affects all major Apple operating systems: iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Versions of these platforms prior to 26.5 are vulnerable; version 26.5 on each platform contains the fix.
Risk and Exploitability
The CVSS score of 4.3 reflects low severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation. The weakness permits attackers to deliver malicious web content, though the CVE description does not specify a delivery method; it is inferred that such content could be served via phishing or malicious websites. It is not listed in CISA KEV, suggesting no widespread, actively exploited incidents are known.
OpenCVE Enrichment