Impact
Improper state management in Safari’s rendering engine leads to memory corruption and inappropriate control flow, as indicated by the referenced CWE‑120 and CWE‑703 weaknesses. When the browser processes maliciously crafted web content, the flaw can cause a crash, terminating the process and resulting in a denial‑of‑service condition. The impact is limited to loss of availability; it does not compromise data confidentiality or integrity.
Affected Systems
Apple Safari on macOS, iOS, and iPadOS is affected. Versions prior to Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2 contain the flaw and have been fixed in the listed release or newer ones.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of < 1 % suggests a low probability of exploitation observed to date. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the crash by serving maliciously crafted web pages from any website or embedded content such as links in email. No special privileges are required, making the threat available to any user who visits the compromised content.
OpenCVE Enrichment