Impact
A use‑after‑free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash. Because the flaw does not enable remote code execution or data exfiltration, its primary consequence is a denial of service from terminating renderer or related processes.
Affected Systems
The vulnerability affects Apple Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS. Versions prior to Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6 are susceptible. The fix is incorporated in the mentioned versions and later.
Risk and Exploitability
The EPSS score is less than 1 percent and the vulnerability is not listed in CISA’s KEV catalog, indicating no widespread exploitation is currently known. The likely attack vector is via malicious web content rendered by Safari or other affected Apple operating systems, requiring the victim to load a crafted page. The CVSS score of 6.5 reflects a moderate severity: the flaw does not grant code execution but can crash processes, leading to a disruptive denial of service. Updating to the patched versions mitigates the risk.
OpenCVE Enrichment