Impact
An out-of-bounds access issue was addressed with improved bounds checking. The vulnerability can be triggered by maliciously crafted web content, resulting in an unexpected crash of Safari or system process. The flaw does not allow arbitrary code execution but leads to denial of service for users interacting with affected pages.
Affected Systems
Apple Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS are affected. Versions prior to Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6 are vulnerable; the issue is fixed in those releases.
Risk and Exploitability
Based on the description, it is inferred that the exploit requires an attacker to serve or embed malicious content that is processed by the affected product, representing a remote attack vector but requiring no elevated privileges. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 indicates a medium severity, yet the potential for widespread disruption depends on the scale of affected devices.
OpenCVE Enrichment