Impact
Apple devices exhibit a memory corruption flaw that can be triggered by processing maliciously crafted web content. The issue has been addressed with improved memory handling and is fixed in iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27, and watchOS 27. Processing such content may lead to memory corruption.
Affected Systems
Apple iOS, iPadOS, macOS, visionOS, and watchOS devices running release versions prior to iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, affected. Updated releases contain enhanced memory handling that mitigates the flaw.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity for a memory corruption flaw. The EPSS score of less than 1% signals a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the delivery of malicious web content, such as through compromised websites or phishing emails, which may trigger memory corruption when processed by the browser or webview components.
OpenCVE Enrichment