Impact
Improper memory handling in Apple operating systems’ web content rendering components can cause an unexpected process crash when maliciously crafted pages are processed. The crash results in a denial of service on the affected device or application, with no evidence that the vulnerability enables code execution, persistence, or compromise of confidentiality or integrity.
Affected Systems
Apple iOS, iPadOS, macOS (codename Tahoe), tvOS, and watchOS are affected in all builds prior to the 26.5 release. Devices running any version older than iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, or watchOS 26.5 are susceptible; updating to the 26.5 update for each platform removes the faulty memory handling logic.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of large‑scale exploitation. The flaw can nevertheless be triggered remotely by serving maliciously crafted web pages or web‑view content to an affected device, resulting in a process crash and denial of service. Although the CVSS score of 7.5 classifies the issue as high severity, the limited exploitability moderates the overall risk.
OpenCVE Enrichment