Impact
An issue in Apple’s memory management allows a use‑after‑free scenario when processing specially crafted web content. The vulnerability can cause an unexpected crash of the browser or application, leading to a denial of service for the affected user. The description does not indicate any escalation of privilege or data disclosure; the impact is limited to interruption of service.
Affected Systems
The flaw affects Apple’s Safari browser, iOS, iPadOS, and macOS (macOS Tahoe). The fix is delivered in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2. Users of earlier releases are vulnerable.
Risk and Exploitability
No CVSS score or EPSS value is supplied, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector appears to be delivery of malicious web content; thus, an attacker would need to entice the user to load the crafted page or a compromised site. While the risk of exploitation is not quantified, the inability to execute arbitrary code or gain elevated privileges reduces the overall threat level; the primary concern remains denial of service through browser crashes.
OpenCVE Enrichment