Impact
The vulnerability is a use‑after‑free bug that can be triggered by maliciously crafted web content viewed in Safari, iOS, iPadOS, and macOS. When the defective memory management is exercised, the browser or system process crashes unexpectedly, interrupting the user’s session. The impact is a local denial of service; the browser quits, or on macOS the affected process terminates, requiring a restart to resume normal operation. No escalation or remote code execution is described.
Affected Systems
Apple’s Safari browser and the WebKit engine are vulnerable on macOS, iOS, and iPadOS devices running versions prior to 26.5.2. The security update that removes the flaw is available in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2. Devices with earlier releases or other macOS versions that have not been patched remain susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score is not publicly available. The vulnerability is not listed in the CISA KEV catalog, and there is no evidence of a remote code execution vector. Attackers are likely to deliver malicious content via a normal web page or other Internet‑accessible resource; no privileged access or user interaction beyond visiting the content is required. The exploitation requires that the target device render the crafted page, causing a crash that cuts short the browsing session. Overall, the risk level is moderate, with a moderate likelihood of exploitation if attackers target popular sites that can embed the vulnerable payload.
OpenCVE Enrichment