Impact
A use‑after‑free flaw (CWE‑416) was discovered in Apple’s Safari browser and its related operating systems. The defect was addressed by improving memory management, and the issue is fixed in Safari 26.5.2, iOS, iPadOS, macOS (Tahoe) 26.5.2, tvOS, visionOS, and watchOS 26.6. Nevertheless, processing maliciously crafted web content can still trigger a use‑after‑free that leads to an unexpected process crash. This denial‑of‑service effect can interrupt browsing or app usage but does not enable arbitrary code execution. The CVSS score of 6.5 indicates moderate severity, and no known exploitation in the wild has been reported.
Affected Systems
The vulnerability affects Apple Safari, the iOS and iPadOS operating systems, and macOS Tahoe on all versions prior to 26.5.2. Apple’s advisory states that the issue is resolved in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2, implying that older software releases remain vulnerable. In addition, tvOS, visionOS, and watchOS are also vulnerable in releases before 26.6.
Risk and Exploitability
The vulnerability does not provide direct code execution or other high‑impact effects; the primary risk is a denial‑of‑service crash. The CVSS score is 6.5, indicating a moderate severity, and the EPSS score of < 1% shows a very low exploitation probability. The flaw is not listed in CISA’s KEV catalog, indicating no widespread exploitation data. The likely attack vector is exposure to malicious or unknown web content, making user browsing habits a key factor. As the flaw hinges on a use‑after‑free error, basic defensive controls such as keeping software up to date provide sufficient protection.
OpenCVE Enrichment
Debian DSA