Impact
A memory corruption vulnerability in Safari, caused by improper locking, is triggered by maliciously crafted web content and may produce an unexpected crash. Apple has addressed the issue with improved locking and released fix versions Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2. The crash leads to denial of service but does not provide arbitrary code execution.
Affected Systems
Apple devices running Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2 are affected. Users should verify their OS and Safari version and upgrade to a release that includes the fix.
Risk and Exploitability
The CVSS score of 3.1 indicates a low severity indicator. With an EPSS score of <1% and no listing in KEV, the probability of exploitation remains low. Based on the description, it is inferred that the vulnerability can be triggered by delivering malicious web content to a victim’s Safari browser, leading to a crash that denies service. Attackers would need to persuade the user to load the malicious content.
OpenCVE Enrichment