Impact
The vulnerability stems from a memory‑corruption flaw in Safari’s web content processing, specifically an out‑of‑bounds read/write (CWE‑119) and buffer overflow (CWE‑120). It was addressed with improved memory handling and is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27. Crafting a malicious web page can trigger this flaw, causing Safari to crash for the user. The crash is limited to Safari; the CVE does not describe additional system impact.
Affected Systems
Apple iOS and iPadOS devices running any version prior to iOS 18.7.10, iOS 26.6.1, iPadOS 18.7.10, or iPadOS 26.6.1, and macOS Tahoe versions older than 26.6.2 are not yet patched. The memory‑handling fix is included in those updates, so earlier builds likely remain vulnerable, though the data does not explicitly list affected releases. VisionOS versions older than 27 are also likely vulnerable.
Risk and Exploitability
The CVSS score is 4.3 and EPSS score is less than 1%. The vulnerability is not listed in the CISA KEV catalog. Processing maliciously crafted web content may lead to an unexpected Safari crash. The flaw is client‑side and confined to Safari, so an attacker would need to entice a user to open the crafted content to trigger the.
OpenCVE Enrichment