Impact
The vulnerability is a use‑after‑free flaw in Apple’s WebKitGTK rendering engine caused by inadequate memory management. When a browser or web view processes maliciously crafted web content, it can access an object that has already been freed, resulting in a memory corruption fault. This could potentially allow attackers to alter program state or execute arbitrary code, threatening confidentiality, integrity, or availability of the device.
Affected Systems
Apple products – Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS – are affected by releases prior to Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The EPSS score of 0.26% indicates a very low but nonzero exploitation probability. The CVSS score of 8.8 demonstrates high severity, emphasizing the risk of memory corruption that could be leveraged for privilege escalation or remote code execution if an attacker can inject or drive crafted content through Safari or system web components. This vulnerability is not listed in the CISA KEV catalog, reducing the likelihood that known exploit payloads are actively used. The likely attack vector involves visiting malicious web pages or loading infected resources in affected Apple browsers or web views.
OpenCVE Enrichment
Debian DSA