Impact
Apple’s WebKitGTK engine contains a memory‑handling flaw that can be triggered by maliciously crafted web pages. When such content is processed, a buffer overrun or unsafe copy leads to an unexpected process crash, which manifests as a denial of service for the user or host application. The weakness is documented as CWE‑119 (Buffer Overflow) and CWE‑120 (Incorrect Calculation of Buffer Length).
Affected Systems
Safari 26.5, iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, and visionOS 26.5 receive the fix. Versions of these products before 26.5 remain vulnerable. The vulnerability also affects the underlying WebKitGTK components integrated into these OS and browser releases.
Risk and Exploitability
Exploiting this flaw requires delivering a specially crafted web page that the victim’s browser or WebKitGTK engine will load; no authentication or elevated privileges are necessary beyond normal browsing. The EPSS score is < 1 %, indicating a very low likelihood of exploitation at present, and the CVSS score of 7.5 represents a moderate to high severity. The vulnerability is not listed in the CISA KEV catalog. The impact is significant enough that any device rendering untrusted web content could be brought to a denial‑of‑service state if the flaw is triggered.
OpenCVE Enrichment