Impact
The vulnerability, now fixed in Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27, involves maliciously crafted web content that previously could trigger an unexpected Safari crash. The flaw relates to a buffer overflow or out‑of‑bounds access (CWE‑119, CWE‑20). An attacker could cause the Safari process to terminate, leading to a temporary denial of service for the application, but does not compromise other system components.
Affected Systems
Apple Safari browsers on iOS, iPadOS, macOS, and visionOS versions that precede Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, or visionOS 27 are vulnerable. Devices with the latest updates are not affected.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity, and the EPSS score is below 1 %, suggesting a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, and current evidence infers that the attack vector requires a user to visit a malicious web page that contains crafted content that Safari must parse.
OpenCVE Enrichment