Impact
A use‑after‑free flaw was discovered in Safari’s memory handling. The issue is mitigated by improved memory management in newer releases. A malicious web page that triggers the use‑after‑free can cause Safari to terminate unexpectedly. The crash is confined to the browser process and does not execute arbitrary code, but it renders Safari unusable for that session.
Affected Systems
Apple Safari, iOS, iPadOS, macOS Tahoe, tvOS, and watchOS are affected by releases prior to 26.5.2 (Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6). The vulnerability is resolved in those updated releases.
Risk and Exploitability
The vulnerability can be triggered via malicious web content, implying an attack vector that relies on a web page served over a network. The exploitation results in a Safari process crash on macOS, iOS, iPadOS, tvOS, and watchOS, thereby denying service to the user session. Because the crash does not lead to code execution or data exfiltration, risks to confidentiality or integrity are limited; the primary impact is loss of availability for browsing activities. The CVSS score of 6.5 indicates moderate risk. The EPSS score is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog.
OpenCVE Enrichment