Impact
This vulnerability arises from Safari's state management handling of web content. Processing maliciously crafted web content may lead to an unexpected Safari crash, resulting in a denial of service on the affected device. Apple states that the issue is fixed in Safari 26.6.1, iOS 18.7.10 and 26.6.1, iPadOS 18.7.10 and 26.6.1, and macOS Tahoe 26.6.2. No evidence of confidentiality or integrity compromise is reported.
Affected Systems
The affected products are Apple Safari on iOS, iPadOS, and macOS (Tahoe). Devices running iOS 18.7.10 or iOS 26.6.1, iPadOS 18.7.10 or iPadOS 26.6.1, or macOS Tahoe 26.6.2 have the issue fixed; any earlier version is impacted.
Risk and Exploitability
The EPSS score of <1% indicates a low probability of exploitation, and the CVSS score of 4.3 reflects a moderate impact. Based on the description, it is inferred that the attack vector is client‑side via loading malicious web content in Safari, requiring no elevated privileges. Although the likelihood of widespread exploitation remains uncertain, the local denial of service could occur on any device exposed to such content, posing a risk to availability for users and organizations relying on Safari.
OpenCVE Enrichment