Impact
Apple reported that maliciously crafted web content may trigger an unexpected crash in Safari due to a memory corruption flaw involving improper bounds checking (CWE‑119) and unsafe handling of input buffers (CWE‑120). The crash results in a denial of service on the affected device. The issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27. No evidence of data loss or unauthorized access was disclosed.
Affected Systems
The affected products are Apple Safari on iOS, iPadOS, macOS (Tahoe), and visionOS. Devices running iOS 18.7.10 or iOS 26.6.1, iPadOS 18.7.10 or iPadOS 26.6.1, macOS Tahoe 26.6.2, or visionOS 27 have the issue fixed; any earlier version is impacted.
Risk and Exploitability
The EPSS score of <1% indicates a low probability of exploitation, and the CVSS score of 4.3 reflects a moderate impact. Based on the description, it is inferred that the attack vector is client‑side via loading malicious web content in Safari, requiring no elevated privileges. Although the likelihood of widespread exploitation remains uncertain, the local denial of service could occur on any device exposed to such content, posing a risk to availability for users and organizations relying on Safari.
OpenCVE Enrichment