Impact
A stack overflow arises when Safari processes specially crafted web content. The flaw was addressed through improved input validation in version 26.5.2 and later across Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS. If malicious content is delivered, the browser may crash, resulting in a denial‑of‑service condition. The bug is a stack‑smashing issue (CWE‑121) and does not allow code execution or data exfiltration.
Affected Systems
Apple’s Safari web browser, iOS, iPadOS, macOS Tahoe, tvOS, visionOS and watchOS are affected. The vulnerability is addressed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6 and watchOS 26.6. Devices running older releases without the patch remain vulnerable.
Risk and Exploitability
A stack overflow arises when Safari processes specially crafted web content, potentially causing the browser to crash unexpectedly. With a CVSS score of 6.5 the flaw is of moderate severity. EPSS score of 0.00437 indicates a very low exploitation probability, and the flaw is not listed in CISA KEV, indicating no confirmed exploitation. The vulnerability requires delivery of malicious web content, so it can be triggered by an attacker who hosts or lures the victim to a crafted page. The crash limits the potential damage to a denial‑of‑service event on a single device. Nonetheless, patching is recommended to prevent abuse via the crash.
OpenCVE Enrichment