Impact
The vulnerability is a memory corruption flaw triggered when the operating system processes maliciously crafted web content. It results from improper memory handling during rendering, which can corrupt internal data structures and potentially lead to memory corruption. While the description does not detail the exact consequences, such memory corruption raises concerns about system stability and security.
Affected Systems
Apple Safari, Apple iOS, Apple iPadOS, and Apple macOS are affected. The flaw was fixed in Safari 26.6.1, iOS 18.7.10 and 26.6.1, iPadOS 18.7.10 and 26.6.1, and macOS Tahoe 26.6.2. Users running earlier releases of any of these products are at risk of memory corruption when rendering web content.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity level, while the EPSS score of less than 1% suggests that exploitation is currently unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the most probable attack vector involves delivering maliciously crafted web pages or content that is rendered by Safari or the web content framework of the operating system. The memory corruption could lead to undefined behavior, potentially affecting confidentiality, integrity, and availability of the affected systems.
OpenCVE Enrichment