Impact
A use‑after‑free vulnerability in Safari enables attackers to send malicious web content that causes the browser to dereference freed memory, leading to an unexpected crash. The issue is confined to the web rendering engine and does not grant attackers code execution or privilege escalation; it results in a denial‑of‑service by terminating the browser instance. The vulnerability is mitigated in Safari 26.6 and newer, iOS 26.6/26.7/27 and iPadOS 26.6/26.7/27, macOS Golden Gate 27 and Tahoe 26.6, tvOS 26.6, visionOS 26.6/27, and watchOS 26.6.
Affected Systems
Apple Safari, iOS, iPadOS, Apple macOS, tvOS, visionOS, and watchOS. Versions before 26.6 of each product are affected; the issue is iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.
Risk and Exploitability
The vulnerability is not publicly associated with a known exploit and is not listed in CISA’s KEV catalog. The CVSS score of 5.5 indicates moderate severity. The EPSS score of <1% indicates a very low but nonzero exploitation probability web content to a user’s Safari session;. The impact is limited to a denial‑of‑service by crashing the browser.
OpenCVE Enrichment