Impact
An issue with Apple’s memory management causes a use‑after‑free when processing maliciously crafted web content, leading to an unexpected process crash. The vulnerability can cause a denial of service for the affected user. The description does not indicate privilege escalation or data disclosure; the impact is limited to interruption of service. It is inferred that the attacker must supply malicious web content to trigger the crash.
Affected Systems
The flaw affects Apple’s Safari browser, iOS, iPadOS, macOS (macOS Tahoe), tvOS, visionOS, and watchOS. The fix is delivered in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. Users of earlier releases are vulnerable.
Risk and Exploitability
The CVSS score is 6.5, the EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog. It is inferred that the attack vector involves delivery of a crafted page or compromised site that a user visits. While the risk of exploitation is low based on the EPSS, the lack of arbitrary code execution or privilege escalation limits the overall threat; the primary concern remains denial of service through browser crashes.
OpenCVE Enrichment
Debian DSA