Impact
An out-of-bounds access flaw in Safari and several Apple operating systems was disclosed. When a user processes maliciously crafted web content, the missing bounds-checking allows the browser to read or write beyond the intended memory region, resulting in an unexpected crash. The vulnerability does not provide elevated privileges or code execution; it only causes a denial of service by forcing Safari to terminate.
Affected Systems
Affected products include Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS. The vulnerability is present in versions released before 26.6 and has been fixed in Safari 26.6, iOS 26.6, iPadOS 26.6, macOS 26.6 (Tahoe), tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The exploit requires an attacker to deliver malicious web content to a victim’s browser, such as by hosting a compromised page or embedding the payload in a link. Because the flaw leads only to a crash and does not enable code execution or privilege escalation, the overall risk is primarily denial of service; it does not compromise confidentiality or integrity. The EPSS score of <1% indicates a very low probability of exploitation, though not zero, and the vulnerability is not listed in CISA’s KEV catalog, indicating that public exploitation is not widely reported. The CVSS score of 8.1 indicates high severity, but the very low EPSS suggests limited public exploitation.
OpenCVE Enrichment