Impact
A use-after-free error in Safari and its companion Apple platforms can be triggered by maliciously crafted web content, resulting in an unexpected crash of the browser application.
Affected Systems
Apple Safari, iOS, iPadOS, Apple macOS, tvOS, visionOS, and watchOS. Versions before 26.6 of each product are affected; the issue is fixed in 26.6 and later releases of Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.
Risk and Exploitability
The vulnerability is not publicly associated with a known exploit and is not listed in CISA’s KEV catalog. The CVSS score of 5.5 indicates moderate severity. The EPSS score of <1% indicates a very low but nonzero exploitation probability. Attackers would need to deliver malicious web content to a user’s Safari session; no privileged state or remote code execution is indicated. The impact is limited to a denial‑of‑service by crashing the browser.
OpenCVE Enrichment