Impact
The vulnerability is a use‑after‑free issue that was addressed by improving memory management. The flaw, classified as CWE‑416, is fixed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, iOS 26.7, iPadOS 26.7, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption, which can cause application crashes or potentially allow an attacker to gain unauthorized control.
Affected Systems
Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are the affected products. Versions older than 26.5.2 (for Safari, iOS, iPadOS, macOS) or 26.6 (for tvOS, visionOS, watchOS) contain the flaw; the issue was addressed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, iOS 26.7, iPadOS 26.7, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity and the EPSS score is < 1%. The vulnerability is not listed in CISA's KEV catalog. The flaw requires the processing of malicious web content to trigger the use‑after‑free. Based on the description, it is inferred that an attacker could craft such content to exploit the flaw, leading to memory corruption.
OpenCVE Enrichment
Debian DSA
Ubuntu USN