Impact
This vulnerability allows the WebKit browser engine used in Safari to terminate unexpectedly when it processes maliciously crafted web content. The crash is triggered by a failure in state management, which was addressed through improved state management in the fix. The resulting denial of service is limited to the loss of the browsing session; no information is disclosed or modified, and there is no compromise of data integrity or confidentiality.
Affected Systems
Apple Safari running on macOS, iOS, iPadOS, and visionOS is affected on all releases prior to Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27. The issue was addressed in Safari 26.6.1, iOS 18.7.10/iPadOS 18.7.10, iOS 26.6.1/iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27 and in all later releases.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of <1% suggests a low probability of exploitation at present. The flaw is not listed in the CISA KEV catalog. The likely attack vector is inferred to be any malicious web page or embedded content that a user may encounter during normal browsing or via an email link, as the flaw does not require elevated privileges and is triggered simply by rendering specially crafted content.
OpenCVE Enrichment