Impact
The vulnerability is triggered when Safari processes maliciously crafted web content that lacks proper input validation, leading to an unexpected crash due to insufficient checks. This crash causes a denial‑of‑service for the user. The failure is limited to the Safari application and does not directly affect system files or data, though repeated crashes can disrupt user workflows.
Affected Systems
Apple Safari browsers on iOS, iPadOS, and macOS with versions earlier than Safari 26.6.1 are affected. The vulnerability is resolved by installing Safari 26.6.1 or later, along with the corresponding iOS 18.7.10 or iOS 26.6.1, iPadOS 18.7.10 or 26.6.1, and macOS Tahoe 26.6.2 updates.
Risk and Exploitability
The CVSS score is 4.3, indicating a medium severity denial‑of‑service. The EPSS score is below 1%, implying a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no large‑scale active exploitation. The likely attack vector relies on user interaction; a single visit to a crafted web page could trigger the crash. The exploit requires the browser to parse the malicious content, making it a user‑dependent vector.
OpenCVE Enrichment