Impact
The vulnerability is a use‑after‑free flaw that can be triggered when Apple’s WebKitGTK components, used in Safari, iOS, iPadOS, macOS, tvOS, visionOS, or watchOS, process maliciously crafted web content. The flaw, classified as CWE‑416, may corrupt memory by freeing an object that is still in use. The description does not elaborate on downstream effects, but memory corruption could result in application crashes or, in some execution contexts, provide an attacker with a foothold for further compromise.
Affected Systems
Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are the affected products. Versions older than 26.5.2 (for Safari, iOS, iPadOS, macOS) or 26.6 (for tvOS, visionOS, watchOS) contain the flaw; the issue was addressed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity and the EPSS score is < 1%. The vulnerability is not listed in CISA's KEV catalog. The flaw requires the processing of malicious web content to trigger the use‑after‑free. Based on the description, it is inferred that an attacker could craft such content to exploit the flaw, leading to memory corruption.
OpenCVE Enrichment
Debian DSA