Impact
An out‑of‑bounds access in Safari allows an attacker to cause a crash when the browser processes maliciously crafted web content. The flaw is mitigated by improved bounds checking, and the issue can lead to an unexpected Safari crash. The weakness is a classic bounds‑overread that can destabilize the browser process, allowing an attacker to interrupt user sessions or interfere with normally functioning interfaces.
Affected Systems
Apple Safari, Apple iOS, Apple iPadOS, and Apple macOS Tahoe are affected. Versions earlier than Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, and macOS Tahoe 26.5.2 are vulnerable. The bug is addressed in the 26.5.2 security updates for all three platforms.
Risk and Exploitability
The vulnerability can be triggered by loading malicious web pages and may be remotely exploitable through the network. No EPSS score is available, and the issue is not listed in CISA KEV. Although no known exploit code exists, the crash can be repeatedly invoked, leading to denial of service for users.
OpenCVE Enrichment