Impact
The vulnerability arises from a flaw in Safari’s state management. When the browser processes maliciously crafted web content, the improper handling causes Safari to crash unexpectedly. This crash terminates the browsing session, resulting in a denial of service for the user. No capability for persistence or data exfiltration is indicated, limiting the impact to service interruption.
Affected Systems
Apple Safari on iOS, iPadOS, macOS, and visionOS. The affected releases are iOS 18.7.10 and 26.6.1, iPadOS 18.7.10 and 26.6.1, macOS Tahoe 26.6.2, visionOS 27, and Safari 26.6.1. These operating system and browser versions are vulnerable when a user renders specially crafted web pages.
Risk and Exploitability
The CVSS score of 4.3 denotes moderate severity, and the EPSS score of < 1% indicates low evidence of exploitation. The vulnerability is not listed in the CISA KEV catalog. It can be exploited by delivering crafted web content to a user’s Safari browser; the attack vector is therefore a malicious website accessed via the affected browser.
OpenCVE Enrichment