Impact
Processing maliciously crafted web content may lead to an unexpected process crash. The flaw does not enable code execution or data theft; it is a denial‑of‑service risk by destabilizing the affected process. The underlying issue is a buffer or memory access violation, consistent with CWEs 119 and 120 weaknesses. The issue was addressed with improved memory handling, and the fix is shipped in Safari 26.5, iOS 26.5, iPadOS 26.5, macOS 26.5, tvOS 26.5, visionOS 26.5 and watchOS 26.5.
Affected Systems
The issue affects Safari and all major Apple operating systems: iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Versions of these platforms prior to 26.5 are vulnerable; version 26.5 on each platform contains the fix.
Risk and Exploitability
The CVSS score of 4.3 reflects low severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation. The weakness permits attackers to deliver malicious web content, though the CVE description does not specify a delivery method; it is inferred that such content could be served via phishing or malicious websites. It is not listed in CISA KEV, suggesting no widespread, actively exploited incidents are known.
OpenCVE Enrichment