Impact
A memory corruption flaw was found in the web rendering components of Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS. The issue was mitigated by improving memory handling, but prior to the fix, maliciously crafted web content could trigger it and lead to an unexpected process crash. This defect is a classic buffer overflow identified as CWE‑119, disrupting browsing and Web‑dependent functions.
Affected Systems
Apple Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS are vulnerable when running versions prior to 26.5.2 (Safari, iOS, iPadOS, macOS Tahoe) or 26.6 (tvOS, visionOS, watchOS). The bug has been fixed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, suggesting no known active exploitation. A potential attacker can cause a crash by directing a user to maliciously crafted web content, but no confirmed exploits are documented. With a CVSS score of 6.5, the vulnerability is considered medium severity, though the crash capability indicates a significant impact on availability.
OpenCVE Enrichment
Debian DSA