Impact
The vulnerability is a memory corruption flaw in Safari’s state management that can be triggered by maliciously crafted web content, leading to an unexpected Safari crash and effectively denying service to users. The issue has been fixed in Safari 26.6.1, iOS 18.7.10 and 26.6.1, iPadOS 18.7.10 and 26.6.1, and macOS Tahoe 26.6.2.
Affected Systems
The flaw affects Apple devices running iOS and iPadOS versions prior to iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, as well as macOS Tahoe versions prior to 26.6.2. Users on any older Apple operating system are potentially exposed.
Risk and Exploitability
The CVSS score of 4.3 places the flaw in a low severity range, while the EPSS score of <1% indicates a very low probability of active exploitation. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. Based on the description, the attack vector is a web context: an attacker must host or serve malicious content that a user’s Safari instance renders; no elevated privileges or additional conditions are required for the crash to occur.
OpenCVE Enrichment