Impact
A flaw in Safari's state management, before being addressed through improved state handling in later releases, allows maliciously crafted web content to trigger an unexpected crash. This crash results in a denial‑of‑service that can disrupt user sessions. The vulnerability originates from improper input handling that bypasses expected bounds or validation checks, leading to an unrecoverable error within the browser process.
Affected Systems
Affected systems include Apple iOS and iPadOS devices running versions prior to iOS 18.7.10 or iOS 26.6.1, and macOS Tahoe versions prior to 26.6.2. The vulnerability is present in Safari integrated with these operating systems.
Risk and Exploitability
The CVSS score is 4.3. The EPSS score is less than 1%, which indicates a very low probability of exploitation. No active exploitation evidence is reported and the impact is limited to a Safari crash, so the overall risk is considered moderate. The vulnerability can be exploited by delivering specially crafted web content, such as through a link, an embedded frame, or a malicious website, making it a remote threat that does not require local privileges.
OpenCVE Enrichment