Impact
The issue is an improper memory handling flaw in Apple WebKitGTK that processes maliciously crafted web content. When such content is rendered, an unexpected process crash can occur, causing a denial‑of‑service condition. The flaw does not allow remote code execution or privilege escalation. The referenced CWEs, CWE-119 and CWE-416, indicate a type‑of‑memory‑corruption fault and a use‑after‑free condition.
Affected Systems
Apple Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS are impacted. The flaw has been fixed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. Earlier releases of these operating systems remain vulnerable.
Risk and Exploitability
The description does not explicitly state the attack vector; it is inferred that an attacker could deliver malicious web content via a compromised website or network element to trigger the crash. The CVSS score of 6.5 indicates moderate severity. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DSA