Impact
The issue was addressed with improved memory handling. This memory handling bug in Apple WebKitGTK can cause an unexpected process crash when maliciously crafted web content is processed. The crash results in a denial‑of‑service condition; it does not allow code execution or privilege escalation. The referenced weaknesses are a type‑of‑memory‑corruption fault (CWE‑119) and a use‑after‑free condition (CWE‑416).
Affected Systems
Apple Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS are impacted. The flaw has been fixed in Safari 26.5.2, iOS 18.7.10 and 26.5.2, iPadOS 18.7.10 and 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. Earlier releases of these operating systems remain vulnerable.
Risk and Exploitability
The description does not explicitly state the attack vector; it is inferred that an attacker could deliver malicious web content via a compromised website or network element to trigger the crash. The CVSS score of 6.5 indicates moderate severity. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DSA
Ubuntu USN