Impact
Apple’s Safari, iOS, iPadOS, and macOS Tahoe are affected by a memory handling flaw that can be triggered by maliciously crafted web content. When the vulnerable rendering engine processes such content, the improper memory management causes an unexpected crash of the browser or related system process. The crash does not give an attacker code execution or data exfiltration capabilities; it simply terminates the affected application, leading to loss of service for the user. The weakness maps to common improper memory management issues such as buffer overread, use‑after‑free, and bad pointer dereference.
Affected Systems
Versions of Safari, iOS, iPadOS, and macOS Tahoe older than 26.5.2 are impacted. An attacker can exploit the vulnerability on any device running a prior version of these products when a user visits or renders malicious web content.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate threat. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of widespread active exploitation at present. Attackers need to lure a user to a malicious page or otherwise load the problematic content; the exploit does not involve a network‑based remote trigger. Thus the principal risk remains localized denial of service on the compromised device.
OpenCVE Enrichment