Impact
A memory corruption flaw caused by improper locking in Safari can be triggered by maliciously crafted web content, leading to an unexpected crash that denies service to users.
Affected Systems
Apple devices running iOS and iPadOS versions 18.7.10, 26.6.1, and macOS Tahoe 26.6.2 are affected. Users should check their OS version and update to the release that contains the fix.
Risk and Exploitability
The CVSS severity is not provided, but the vulnerability can be exploited by delivering crafted HTML or JavaScript to a victim’s Safari browser. With an unavailable EPSS score and no listing in KEV, the exact likelihood of exploitation remains uncertain, yet the potential for denial of service is high. Attackers would need to convince the user to load the malicious content.
OpenCVE Enrichment