Impact
The vulnerability involves improper input validation, designated as CWE‑20, in Safari’s rendering engine. Processing maliciously crafted web content may lead to an unexpected crash. Apple has addressed the issue by improving input validation in Safari 26.6.1 and the corresponding releases of iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27, which is restarted or patched, resulting in a denial of service for the user without leaking data or escalating privileges.
Affected Systems
Apple’s mobile operating systems iOS and iPadOS, macOS Tahoe, and visionOS are affected. The flaw was fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity on availability. The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploits. Exoitation would require a user to load malicious content in Safari, making the attack vector user‑centric. While the likelihood of exploitation is presently low, promptly applying the update is recommended to maintain service continuity.
OpenCVE Enrichment