Impact
The vulnerability stems from unsafe memory handling within Safari, where maliciously crafted web content can trigger a crash. The crash causes Safari to terminate unexpectedly, resulting in a local denial-of-service condition for the device. There is no evidence that the flaw permits code execution or remote compromise.
Affected Systems
Apple’s Safari on macOS, iOS, iPadOS, tvOS, visionOS, and watchOS is affected. Devices running versions prior to Safari 26.5, iOS 18.7.10, iPadOS 18.7.10, iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, or watchOS 26.5 are vulnerable. The issue is resolved in the releases mentioned above.
Risk and Exploitability
The exploit is likely local, requiring a user to view or interact with harmful web content. The EPSS score is less than 1%, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score is 4.3, indicating a moderate risk for affected users.
OpenCVE Enrichment
Ubuntu USN