Impact
An improper state management flaw leading to resource exhaustion (CWE-400) can cause applications to terminate or become unresponsive when a user visits a particular website. The flaw can result in a denial of service that does not require attacker credentials or rights to the operating system.
Affected Systems
The flaw affects Apple’s Safari browser, iOS, iPadOS, macOS (Tahoe) and visionOS on any versions prior to the 26.6 release. The issue was addressed in Safari 26.6, iOS 26.6, iPadOS 26.6, macOS 26.6, and visionOS 26.6.
Risk and Exploitability
The EPSS score is less than 1 %, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 indicates medium severity. The attack vector is inferred to involve a malicious website that a victim visits; no additional exploitation prerequisites are disclosed in the source material.
OpenCVE Enrichment