Impact
A stack overflow occurs when Safari processes specially crafted web content, causing the browser to crash unexpectedly. This flaw is a stack‑smashing bug (CWE‑121) that disrupts the target application by exhausting critical memory. The impact is a denial of service; the crash does not provide code execution or data exfiltration.
Affected Systems
Apple’s Safari web browser, iOS, iPadOS and macOS Tahoe are affected. The vulnerability is addressed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2 and macOS Tahoe 26.5.2. Devices running older releases without the patch remain vulnerable.
Risk and Exploitability
With a CVSS score of 6.5 the flaw is of moderate severity. EPSS is not available and the flaw is not listed in CISA KEV, indicating no confirmed exploitation. The vulnerability requires delivery of malicious web content, so it can be triggered by an attacker who hosts or lures the victim to a crafted page. The crash limits the potential damage to a denial‑of‑service event on a single device. Nonetheless, patching is recommended to prevent abuse via the crash.
OpenCVE Enrichment