Impact
The vulnerability arises from insufficient memory handling when rendering web content on Apple devices. Maliciously crafted pages can trigger memory corruption, which may affect program execution or cause application crashes, potentially compromising data integrity.
Affected Systems
Apple iOS, iPadOS, and macOS Tahoe versions earlier than 26.6.1, 26.6.1, and 26.6.2 respectively are affected. The fix involves upgrading to these releases or later; devices still running earlier releases remain vulnerable.
Risk and Exploitability
The EPSS score indicates a very low exploitation probability, and the CVSS score of 5.4 reflects a moderate severity for memory corruption. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the delivery of malicious web content, such as through a compromised website or phishing. Processing such content may lead to memory corruption, which could cause application crashes. In some scenarios, memory corruption could allow unintended code execution, an inference drawn from the nature of the flaw.
OpenCVE Enrichment