Impact
An improper state management flaw leads to resource exhaustion (CWE-400, CWE-664) when a user visits a specific website. This can cause applications such as Safari and other Apple operating system apps to terminate or become unresponsive, resulting in a denial of service without requiring attacker credentials or operating‑system privileges.
Affected Systems
Apple Safari, iOS, iPadOS, macOS (Tahoe) and visionOS on any versions prior to 26.6. The flaw was addressed in Safari 26.6, iOS 26.6, iPadOS 26.6, macOS 26.6, and visionOS 26.6.
Risk and Exploitability
The EPSS score is less than 1 %, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 reflects medium severity. The attack vector is inferred to involve a malicious website that a victim visits; no additional exploitation prerequisites are disclosed.
OpenCVE Enrichment
Debian DSA
Ubuntu USN