Impact
The vulnerability is an improper memory handling flaw in Safari, iOS, iPadOS, and macOS. According to the description, maliciously crafted web content can cause an unexpected process crash, resulting in a denial‑of‑service condition. The impact is limited to a process crash; no remote code execution or elevated privilege gain is indicated. The provided CWE identifiers (CWE-119 and CWE-416) confirm a type‑of‑memory‑corruption fault and a use‑after‑free condition.
Affected Systems
Apple Safari, iOS, iPadOS, and macOS Tahoe are impacted. The flaw has been fixed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2. Earlier releases of these operating systems remain vulnerable.
Risk and Exploitability
The description does not explicitly state the attack vector; it is inferred that an attacker could deliver malicious web content via a compromised website or network element to trigger the crash. The CVSS score of 6.5 indicates moderate severity. No EPSS data is available, so exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DSA