Impact
The CVE describes a type confusion flaw in Apple Safari, iOS, iPadOS and macOS Tahoe; this issue was addressed with improved checks. The flaw arises when the runtime incorrectly validates data types while processing web content. According to the description, maliciously crafted content may lead to memory corruption in the affected processes. The impact as described is limited to memory corruption; specific capabilities such as arbitrary code execution are not explicitly stated and therefore not confirmed.
Affected Systems
Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS and watchOS are affected. The fix is implemented in version 26.5.2 for Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS and watchOS. All earlier releases are vulnerable.
Risk and Exploitability
The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, so the exact exploitation chances remain low. Given the CVSS score of 8.8, the vulnerability is considered high severity. The flaw triggers memory corruption when malicious web content is processed, but no public exploitation has been reported, and the description does not confirm that it enables arbitrary code execution or denial of service. The lack of detailed exploitation evidence suggests that while the vulnerability is serious, its exploitation risk remains uncertain.
OpenCVE Enrichment
Debian DSA