Impact
Processing maliciously crafted web content may lead to an unexpected crash of Safari, iOS, iPadOS, macOS, tvOS, visionOS, or watchOS, resulting in an availability loss for the affected application or system. The underlying flaw is a memory handling bug that does not compromise confidentiality or integrity, limiting the impact to service disruption on the affected platform.
Affected Systems
The defect is present in Apple’s Safari browser, iOS, iPadOS, and macOS Tahoe before version 26.5.2. The fixes are incorporated in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6, which all contain improved memory handling for web content.
Risk and Exploitability
EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low exploitation probability. However, a typical attack would involve a remote actor delivering malicious web content to a user’s browser, making the exploitation vector likely remote over HTTP(S). The CVSS score of 6.5 indicates moderate risk.
OpenCVE Enrichment
Debian DSA