Impact
A memory corruption issue, classified as CWE-119 and CWE-120, was addressed with improved state management in Safari. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, and watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. The flaw causes an application failure rather than arbitrary code execution, resulting in a denial‑of‑service impact.
Affected Systems
The flaw affects Safari and its core web rendering components on macOS, iOS, iPadOS, visionOS, and watchOS. Devices running any of these platforms with versions earlier than Safari 26.6, iOS 18.7.10 or 26.6, iPadOS 18.7.10 or 26.6, macOS Tahoe 26.6, visionOS 26.6, or watchOS 26.6 are vulnerable. Apple has released simultaneous fixes: Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low likelihood of exploitation, but the CVSS score of 8.8 classifies it as high severity. No public exploitation data is known and the flaw is not listed in the CISA KEV catalog. The attack vector is inferred to be a remote attacker delivering malicious web content that renders in Safari. Because the flaw leads only to a crash, exploitation risk is limited to denial of service and there are no known mechanisms for code execution or persistent compromise. The vulnerability therefore represents a high risk that can be mitigated by upgrading to the fixed releases.
OpenCVE Enrichment
Debian DSA
Ubuntu USN