Impact
The vulnerability is a use‑after‑free condition that can cause an unexpected process termination when maliciously crafted web content is processed. This results in a denial of service type impact, as the affected process crashes, but does not provide an attacker with code execution or elevated privileges.
Affected Systems
Apple devices running iOS, iPadOS, or macOS are affected. The issue is fixed in iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2; all older releases remain vulnerable.
Risk and Exploitability
Exact CVSS and EPSS scores are not available, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be through malicious web content—e.g., pages served over HTTP/HTTPS or embedded in a web view—indicating that the threat originates from content accessed by users. Exploitation could be automated but would likely be limited to triggering application crashes rather than gaining further foothold on the system.
OpenCVE Enrichment