Impact
This vulnerability is a use‑after‑free bug in Apple's web browsers and operating systems. A crafted web page can trigger accidental deallocation of memory that is still in use, causing the browser or related process to crash. The immediate consequence is a denial of service that disrupts user activity; there is no known escalation to code execution or data exfiltration.
Affected Systems
The flaw affects Apple products announced under the Safari, iOS, iPadOS, and macOS Tahoe families. Versions prior to 26.5.2 of each product contain the vulnerability. The fix is delivered in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.
Risk and Exploitability
No EPSS score is available and the vulnerability is not included in CISA’s KEV catalog, suggesting limited or no evidence of active exploitation. Nevertheless, the attack vector involves delivering malicious content through a web page, meaning any user visiting a compromised site could experience a crash. The lack of a current exploit makes the risk moderate, but the impact of a browser or system process termination warrants prompt remediation.
OpenCVE Enrichment