Impact
A memory corruption vulnerability in Safari occurs because of improper locking when processing maliciously crafted web content. The flaw can corrupt shared memory during parsing, which can cause Safari to crash unexpectedly. The result is a denial‑of‑service in the browser, with no disclosed privilege escalation or data exfiltration. This is a race condition and process synchronization flaw (CWE-362, CWE-667).
Affected Systems
Apple devices running Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27 are affected. The issue is present in Safari on iOS, iPadOS, macOS, and visionOS until the versions above are installed.
Risk and Exploitability
The CVSS score of 3.1 and the EPSS score of less than 1% indicate a low severity and a low probability of exploitation. The vulnerability is not listed in CISA KEV. Attackers would typically need to deliver malicious web content that triggers the parsing problem, which generally requires the victim to visit a compromised or malicious site. No privilege escalation or confidentiality breach is possible from this vulnerability based on the available information.
OpenCVE Enrichment