Impact
The vulnerability stems from improper memory handling during web content rendering, which can cause a process crash. The resulting denial of service disrupts user sessions and system stability and is an example of a memory corruption weakness.
Affected Systems
Apple devices running older releases of iOS, iPadOS, macOS, tvOS, visionOS, and watchOS before the patched versions iOS 18.7.9, iPadOS 18.7.9, iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5 are affected. Updating to these patched OS releases removes the crash risk.
Risk and Exploitability
The CVSS score is 7.5, the EPSS score is < 1%, and the vulnerability is not listed in the KEV catalog. The attack likely involves delivering maliciously crafted web content that exploits the memory handling flaw to trigger a crash. Because the vulnerability can be triggered by crafted content, it poses a high reason for concern yet the EPSS indicates a low probability of exploitation.
OpenCVE Enrichment