Impact
An out‑of‑bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash. The flaw causes a local denial of service by terminating the browser process, but does not permit code execution or privilege escalation.
Affected Systems
The affected products are Apple’s Safari running on iOS, iPadOS, macOS, and visionOS. The CVE notes that the issue is fixed in iOS 18.7.10 and 26.6.1, iPadOS 18.7.10 and 26.6.1, and visionOS 27. Versions prior to these remain at risk.
Risk and Exploitability
The CVSS score of 4.3 reflects moderate impact, while the EPSS score of less than 1% indicates a very low likelihood of exploitation. The exploit requires delivery of malicious web content via Safari, typically through a phishing or malicious website, making the threat realistic but limited. The vulnerability is not catalogued in CISA’s KEV list, further suggesting minimal pressure to exploit.
OpenCVE Enrichment