Impact
The vulnerability is a use‑after‑free flaw in Apple’s web browsers and extensions. Apple has addressed it with improved memory management, and the issue is fixed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. A malicious web extension could trigger a process crash by exploiting the flaw. The impact is a denial of service for the user, with no known code execution or data exfiltration.
Affected Systems
Apple Safari on macOS, as well as the iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS platforms are affected. Versions prior to 26.5.2 of Safari, iOS, iPadOS, macOS Tahoe, tvOS 26.6, visionOS 26.6, and watchOS 26.6 contain the vulnerability. The issue is fixed in the respective 26.5.2 or 26.6 updates.
Risk and Exploitability
Given the EPSS score of 0.00382 (< 1 %), the vulnerability has a very low predicted exploitation probability, and it is not listed in CISA's KEV catalog, indicating no known active exploitation at the time of this report. The flaw can be exploited by any malicious web extension, which is a common vector for browser attacks. The CVSS score of 5.3 indicates moderate severity; the crash still undermines availability and user trust.
OpenCVE Enrichment