Impact
An out-of-bounds access vulnerability was present in Safari and various Apple operating systems, potentially leading to a process crash when maliciously crafted web content is processed. The flaw does not allow arbitrary code execution but causes denial of service for affected users.
Affected Systems
Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. Older versions of these products are vulnerable; the issue has been addressed in newer releases, including Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
Based on the description, it is inferred that the exploit requires an attacker to serve or embed malicious content that is processed by the affected product, representing a remote attack vector but requiring no elevated privileges. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 indicates a medium severity, yet the potential for widespread disruption depends on the scale of affected devices.
OpenCVE Enrichment