Impact
An out-of-bounds access flaw was found in Safari and several Apple operating systems. The bug occurs when maliciously crafted web content is processed, and because bounds checking was insufficient, the browser can read or write beyond the intended memory buffer. The result is an unexpected Safari crash. The flaw does not allow code execution or privilege escalation; it only causes denial of service by terminating the browser.
Affected Systems
Affected products include Safari, iOS, iPadOS, macOS (Tahoe), tvOS, visionOS, and watchOS. The vulnerability exists in versions prior to Safari 26.6 and iOS 26.6, iPadOS 26.6, and macOS 26.6 (Tahoe), with additional fixes provided for iOS 18.7.10 and iPadOS 18.7.10. All listed operating systems and Safari have received a patch in the 26.6 or 18.7.10 releases.
Risk and Exploitability
The exploit requires an attacker to deliver malicious web content to a victim’s browser, such as by hosting a compromised page or embedding the payload in a link. Because the flaw leads only to a crash and does not enable code execution or privilege escalation, the overall risk is primarily denial of service; it does not compromise confidentiality or integrity. The EPSS score of <1% indicates a very low probability of exploitation, though not zero, and the vulnerability is not listed in CISA’s KEV catalog, indicating that public exploitation is not widely reported. The CVSS score of 8.1 indicates high severity, but the very low EPSS suggests limited public exploitation.
OpenCVE Enrichment
Debian DSA
Ubuntu USN