Impact
A flaw in Safari’s state management causes the browser to crash when it processes maliciously crafted web content. The crash terminates the browser, resulting in a denial‑of‑service for the user. No persistence or data exfiltration is described, so the impact is limited to service interruption.
Affected Systems
Apple Safari on iOS and iPadOS 18.7.10, iOS and iPadOS 26.6.1, and macOS Tahoe 26.6.2. These operating system and browser versions are vulnerable when a user renders specially crafted web pages.
Risk and Exploitability
The CVSS score of 4.3 denotes moderate severity, and the EPSS score of < 1% indicates low evidence of exploitation. The vulnerability is not listed in the CISA KEV catalog. It can be exploited by delivering crafted web content to a user’s Safari browser; the attack vector is therefore a malicious website accessed via the affected browser.
OpenCVE Enrichment