Impact
An improper memory handling flaw in Apple’s Safari browser and several operating systems causes the parser that renders web content to crash when it receives maliciously crafted data. The vulnerability results in the termination of the affected process, effectively denying service to users who rely on Safari or the underlying system processes. The weakness is a buffer overflow condition (CWE-119 and CWE-120).
Affected Systems
The flaw affects Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. It is fixed in Safari 26.5, iOS 18.7.9 and 26.5, iPadOS 18.7.9 and 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5; all earlier releases remain vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of <1 % suggests a very low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog and no public exploit has been documented. Based on the description, it is inferred that an attacker could deliver maliciously crafted web pages that the victim’s device loads, triggering the crash; therefore the risk is moderate but can be fully mitigated by applying the available updates.
OpenCVE Enrichment