Impact
A memory corruption vulnerability (CWE-362, CWE-667) was caused by improper locking during content processing in Safari. Maliciously crafted web content can trigger an unexpected Safari crash, resulting in application termination. The issue has been fixed in Safari 26.6.1, iOS 18.7.10 and 26.6.1, iPadOS 18.7.10 and 26.6.1, and macOS Tahoe 26.6.2.
Affected Systems
Apple iOS devices running versions prior to 18.7.10 or 26.6.1, Apple iPadOS devices running versions prior to 18.7.10 or 26.6.1, and Apple macOS Tahoe builds prior to 26.6.2 are affected. All devices that run Safari on those operating systems are vulnerable.
Risk and Exploitability
The vulnerability, a memory corruption involving improper locking (CWE-362, CWE-667), has no known code-execution impact and is limited to a crash that affects availability; the CVSS score is 3.1, indicating low severity. Because the EPSS score is < 1% and it is not listed in the CISA KEV catalog, the likelihood of widespread exploitation appears low. However, malicious actors could craft web pages designed to trigger the crash on vulnerable devices, potentially disrupting services or causing denial of service for users who rely on Safari for critical tasks. The remediation procedure focuses on applying the latest system updates that contain the locking fix.
OpenCVE Enrichment