Impact
Apple’s Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS include a memory handling flaw that can be triggered by maliciously crafted web content. The rendering engine processes such content and experiences an unexpected crash due to improper memory access such as buffer overreads and use‑after‑free. The crash terminates the affected process but does not enable code execution or data exfiltration, so the primary impact is a denial of service on the compromised device.
Affected Systems
Versions of Safari, iOS, and iPadOS older than 26.5.2; macOS Tahoe older than 26.5.2; tvOS, visionOS, and watchOS older than 26.6 are impacted. Any user accessing or rendering maliciously crafted content on these systems may trigger the crash.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score is <1% and the vulnerability is not listed in CISA KEV, suggesting a low likelihood of widespread active exploitation at present. Based on the description, it is inferred that attackers would need to lure a user to a malicious page or otherwise cause the browser to render the problematic content, indicating a user-interaction or browsing model attack vector. The flaw therefore presents a local denial‑of‑service risk rather than a remote network‑level attack.
OpenCVE Enrichment
Debian DSA