Impact
An out‑of‑bounds access issue in Safari’s rendering engine may be triggered by maliciously crafted web content. The problem was addressed with improved bounds checking, and it has been fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, and macOS Tahoe 26.6.2. Before the patch, the vulnerability could cause Safari to crash during page rendering, resulting in a local denial of service. No code execution or privilege escalation is possible.
Affected Systems
The affected products are Apple’s Safari running on iOS, iPadOS, and macOS. The CVE notes that the issue is fixed in iOS 18.7.10 and 26.6.1, iPadOS 18.7.10 and 26.6.1, and macOS Tahoe 26.6.2, but it does not list the specific versions that are vulnerable, so any earlier releases not yet upgraded to these patched versions remain at risk.
Risk and Exploitability
The CVSS score of 4.3 reflects moderate impact, while the EPSS score of less than 1% indicates a very low likelihood of exploitation. The exploit requires delivery of malicious web content via Safari, typically through a phishing or malicious website, making the threat realistic but limited. The vulnerability is not catalogued in CISA’s KEV list, further suggesting minimal pressure to exploit.
OpenCVE Enrichment