Impact
An out‑of‑bounds write issue was addressed with improved input validation, but processing maliciously crafted web content may still trigger a crash in Safari. The vulnerability is confined to the browser process and does not allow remote code execution or data exfiltration. A flaw of this nature leads to a denial‑of‑service for the user through an unexpected browser termination.
Affected Systems
Apple Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS running any version prior to their respective fixed releases (Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6) are vulnerable; the issue was resolved in those releases.
Risk and Exploitability
The CVSS score of 6.5 reflects moderate severity, and the EPSS score is <1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, indicating no known widescale exploitation. The likely attack vector involves delivering maliciously crafted web content to a target’s browser, typically by directing the user to a malicious or compromised website that injects the overflow payload. Successful exploitation would crash Safari but would not compromise system integrity or confidentiality.
OpenCVE Enrichment
Debian DSA