Impact
This issue was addressed through improved state management. Processing maliciously crafted web content may lead to an unexpected Safari crash. The vulnerability causes Safari to crash when rendering such content, resulting in a denial of service for users. It is associated with improper state management (CWE‑703) and buffer handling (CWE‑120).
Affected Systems
Apple iOS, iPadOS, and macOS are affected. The fix is included in iOS 18.7.10 and 26.6.1, iPadOS 18.7.10 and 26.6.1, and macOS Tahoe 26.6.2.
Risk and Exploitability
The likely attack vector is delivering maliciously crafted web content to Safari over the internet, which would trigger a crash on the victim’s browser. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 4.3 indicates moderate impact; while the availability disruption is limited to the user session, the risk remains moderate for end‑users.
OpenCVE Enrichment