Impact
A use-after-free issue was identified in Apple’s web content processing. The flaw is tied to memory management, which is corrected in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. The glitch remains present in earlier releases. When maliciously crafted web content is processed, the double-free can trigger an unexpected process crash, resulting in a denial of service to the user. No evidence of privilege escalation or data disclosure is mentioned, so the compromise is limited to a local interruption of service.
Affected Systems
The flaw affects Apple’s Safari browser, iOS, iPadOS, macOS (macOS Tahoe), tvOS, visionOS, and watchOS. The fix is delivered in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. Users of earlier releases are vulnerable.
Risk and Exploitability
The CVSS score is 6.5, the EPSS score is < 1%, and the vulnerability is not listed in CISA's KEV catalog. It is inferred that the attack vector involves delivery of a crafted page or compromised site that a user visits. While the risk of exploitation is low based on the EPSS, the lack of arbitrary code execution or privilege escalation limits the overall threat; the primary concern remains denial of service through browser crashes.
OpenCVE Enrichment
Debian DSA