Impact
An out‑of‑bounds access flaw in Safari can cause the browser to crash when processing maliciously crafted web content. The weakness originates from insufficient bounds checking, leading to a buffer overrun that destabilizes the process. This results in a denial‑of‑service condition for users.
Affected Systems
Apple Safari, Apple iOS, Apple iPadOS, and Apple macOS Tahoe are vulnerable in versions prior to Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2. The issue is fixed by the 26.5.2 security updates for all platforms.
Risk and Exploitability
The vulnerability can be triggered by loading malicious web pages and is remotely exploitable over the network. It carries a CVSS score of 6.5, indicating medium severity. No EPSS score is available and the flaw is not listed in CISA KEV. Repeated crashes could disrupt user sessions.
OpenCVE Enrichment