Impact
A memory corruption issue caused by improper state handling was identified and addressed with improved state management. The issue can be triggered by maliciously crafted web content that results in an unexpected Safari crash. The severity describes a denial‑of‑service scenario where the affected browser process is terminated, potentially disrupting user activity.
Affected Systems
The flaw affects Apple browsers and operating systems running versions prior to Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2 and visionOS 27. Users on any older Apple operating system are potentially exposed.
Risk and Exploitability
The CVSS score of 4.3 places the flaw in a low severity range, while the EPSS score of <1% indicates a very low probability of active exploitation. The flaw is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely a web context: an attacker must host or serve malicious content that a user’s Safari instance renders; no elevated privileges or additional conditions are required for the crash to occur.
OpenCVE Enrichment