Impact
The vulnerability is a flaw in the memory handling of the web content engine that can be triggered by maliciously crafted web pages. When such content is processed, the affected process may crash, leading to a denial‑of‑service condition for the user or application that relied on that process. This is a pure crash bug with no direct information disclosure or code execution reported.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS and visionOS versions before 26.5 are vulnerable. The fix is delivered in iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5 and visionOS 26.5.
Risk and Exploitability
The exploit requires the attacker to deliver a specially crafted web page that the victim's browser or web engine will load. No authentication or privileges are required beyond normal browsing. The EPSS score is < 1% and the CVSS score is 7.5; the vulnerability is not listed in the CISA KEV catalog; nevertheless, the crash impact is significant enough that any device that processes untrusted web content could be brought to a denial-of-service state.
OpenCVE Enrichment