Description
This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. Visiting a website may lead to an app denial-of-service.
Published: 2026-07-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper state management flaw leading to resource exhaustion (CWE-400) can cause applications to terminate or become unresponsive when a user visits a particular website. The flaw can result in a denial of service that does not require attacker credentials or rights to the operating system.

Affected Systems

The flaw affects Apple’s Safari browser, iOS, iPadOS, macOS (Tahoe) and visionOS on any versions prior to the 26.6 release. The issue was addressed in Safari 26.6, iOS 26.6, iPadOS 26.6, macOS 26.6, and visionOS 26.6.

Risk and Exploitability

The EPSS score is less than 1 %, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 indicates medium severity. The attack vector is inferred to involve a malicious website that a victim visits; no additional exploitation prerequisites are disclosed in the source material.

Generated by OpenCVE AI on August 4, 2026 at 23:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Safari, iOS, iPadOS, macOS, and visionOS to version 26.6 or later
  • Enable automatic software updates on all Apple devices to receive future security patches promptly
  • Consider temporarily disabling JavaScript in Safari via Settings > Safari > Advanced > JavaScript to reduce risk until a patch is available

Generated by OpenCVE AI on August 4, 2026 at 23:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title State Management Flaw Causes App Denial-of-Service in Safari and Apple Operating Systems

Tue, 04 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Denial‑of‑Service via Improper State Management in Safari and Apple System Applications
Weaknesses CWE-20

Thu, 30 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Denial‑of‑Service via Improper State Management in Safari and Apple System Applications
Weaknesses CWE-20

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple visionos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. Visiting a website may lead to an app denial-of-service.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Safari Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T16:00:41.528Z

Reserved: 2026-05-01T22:46:27.821Z

Link: CVE-2026-43804

cve-icon Vulnrichment

Updated: 2026-07-28T16:00:37.248Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:03.650

Modified: 2026-07-28T18:57:36.970

Link: CVE-2026-43804

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T23:45:02Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption