Impact
The vulnerability is a case of improper input validation—CWE‑20—in Safari. The browser fails to properly sanitize maliciously crafted web content, leading to an unexpected crash. Apple addressed the issue with improved input validation in the latest releases of Safari, iOS, iPadOS, and macOS. The crash renders Safari unusable until the device is restarted or patched, constituting a denial of service for the user. The fault does not expose data or privileges, but it disrupts the availability of the browser.
Affected Systems
Apple’s mobile operating systems iOS and iPadOS, and macOS Tahoe are affected. The flaw was fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, and macOS Tahoe 26.6.2.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity on availability. The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploits. Exploitation would require a user to load malicious content in Safari, making the attack vector user‑centric. While the likelihood of exploitation is presently low, promptly applying the update is recommended to maintain service continuity.
OpenCVE Enrichment