Impact
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. The crash can lead to a denial‑of‑service condition for users.
Affected Systems
Apple Safari, Apple iOS, Apple iPadOS, Apple macOS Tahoe, Apple visionOS, and Apple watchOS are vulnerable in versions prior to Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, visionOS 26.6, and watchOS 26.6. The issue is resolved by applying the 26.5.2/26.6 security updates for all platforms.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector involves loading malicious web pages. The vulnerability can be triggered by such loading and is remotely exploitable over the network. It carries a CVSS score of 6.5, indicating medium severity. The EPSS score is 0.364%, suggesting a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Repeated crashes could disrupt user sessions and lead to denial‑of‑service.
OpenCVE Enrichment
Debian DSA