Impact
The vulnerability is a memory handling error that causes an unexpected crash of the affected process when maliciously crafted web content is processed, delivering a denial‑of‑service condition. The weakness is an improper handling of memory resources, classified as CWE‑119.
Affected Systems
Apple systems affected include iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS. The bug exists in versions prior to the fixes applied in iOS 18.7.9, iPadOS 18.7.9, iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5.
Risk and Exploitability
The CVSS score is 7.5, indicating a medium severity. The EPSS score is < 1 %, suggesting a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The documented trigger is the delivery of malicious web content, which represents the primary attack vector. No active exploitation has been reported as of the latest advisory.
OpenCVE Enrichment