Impact
The flaw lies in Safari’s handling of maliciously crafted web content, which can lead to an unexpected crash. Apple has addressed the defect through improved state management, and the vulnerability is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2 and visionOS 27.
Affected Systems
Apple devices running iOS and iPadOS before 18.7.10 and 26.6.1, Safari before 26.6.1, and macOS Tahoe before 26.6.2 are affected until the system is updated to the fixed releases listed above.
Risk and Exploitability
The vulnerability can be triggered by loading malicious web content; the likely attack vector is loading malicious web content based on the description, where an attacker would need to craft a URL or website. The EPSS score is less than 1%, and the vulnerability is not listed in CISA’s KEV catalog. The impact is restricted to availability, producing a Safari crash with no privilege elevation or data compromise (CWE‑120). The CVSS score is 4.3. Updating to the patched releases mitigates the risk.
OpenCVE Enrichment