Impact
The flaw arises from improper handling of internal state within Safari’s state management logic. When maliciously crafted web content is processed, it can trigger an unexpected crash, resulting in a denial‑of‑service that interrupts user activity and risks loss of unsaved data (CWE‑120).
Affected Systems
Apple devices running iOS and iPadOS before 18.7.10 and 26.6.1, Safari before 26.6.1, and macOS Tahoe before 26.6.2 are affected until the system is updated to the fixed releases listed above.
Risk and Exploitability
The vulnerability can be triggered simply by loading malicious web content; the attacker only needs to craft a URL or website. The EPSS score is less than 1%, and the vulnerability is not listed in CISA’s KEV catalog. The impact is restricted to availability, producing a Safari crash with no privilege elevation or data compromise (CWE‑120). The CVSS score is 4.3. Updating to the patched releases mitigates the risk.
OpenCVE Enrichment