Impact
The vulnerability is a use‑after‑free issue addressed by improved memory management. Processing maliciously crafted web content may lead to an unexpected Safari crash, resulting in a denial of service that terminates the browser on the affected device. This disruption does not expose sensitive data. The flaw, classified as CWE‑416, is fixed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, visionOS 26.6, and watchOS 26.6.
Affected Systems
The vulnerability is present in Apple Safari, iOS, iPadOS, macOS Tahoe, visionOS, and watchOS on all releases prior to the respective patched versions. The fix is deployed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, visionOS 26.6, and watchOS 26.6, so only older releases are at risk.
Risk and Exploitability
The attack requires that a user loads malicious web content in Safari. Based on the description, the likely vector is remote through a compromised or intentionally malicious website, and the exploited condition is local to the user's device. A very low EPSS score of 0.00326 indicates a low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 reflects medium severity.
OpenCVE Enrichment
Debian DSA