Impact
Processing maliciously crafted web content may cause Safari to crash due to a flaw in state management. The fault does not give an attacker code execution or data exfiltration, but terminates the browser, leading to a denial‑of‑service condition for the affected user session. The weakness is linked to improper state handling (CWE‑703) and a buffer management issue (CWE‑120).
Affected Systems
Apple’s Safari browser on iOS, iPadOS, macOS and visionOS is affected. The fix is incorporated in Safari 26.6.1, iOS 18.7.10 and 26.6.1, iPadOS 18.7.10 and 26.6.1, macOS Tahoe 26.6.2, and visionOS 27.
Risk and Exploitability
The attack vector is inferred to be the delivery of malicious web content over the internet, which triggers the crash when rendered by Safari. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 4.3 reflects moderate severity for availability disruption; the risk remains moderate for end‑users until a patch is applied.
OpenCVE Enrichment