Impact
A memory corruption flaw in WebKit within Apple’s Safari and related operating systems can be triggered by maliciously crafted web content. The failure arises from insufficient memory handling, resulting in memory corruption that may cause undefined behavior, including potential denial of service or compromise of confidentiality and integrity. The CVSS score of 8.8 classifies it as high severity. The available data indicates that malicious content processed by Safari or other WebKit components can lead to memory corruption, and no other weaknesses are cited.
Affected Systems
Apple’s Safari is affected in version 26.6.1; iOS is affected in releases 18.7.10 and 26.6.1; iPadOS is affected in releases 18.7.10 and 26.6.1; macOS Tahoe is affected in 26.6.2; tvOS is affected in 27; visionOS is affected in 27; and watchOS is affected in 27.
Risk and Exploitability
The high CVSS score underscores the severity, yet the EPSS score of less than 1% indicates a very low likelihood of exploitation currently. The vulnerability is not listed in CISA’s KEV catalog. The most probable attack vector involves delivery of maliciously crafted web pages or content that is rendered by Safari or the platform’s WebKit framework. Because the issue is a memory corruption fault, an attacker achieving exploitation could potentially cause a crash or, under the right conditions, gain control of execution or compromise system data.
OpenCVE Enrichment