Impact
The CVE describes a flaw in Safari’s memory handling that allows maliciously crafted web content to trigger an unexpected crash. The weakness involves improper buffer handling and use‑after‑free, leading to a denial‑of-service. An attacker can exploit this by delivering a crafted web page to a victim using Safari. No arbitrary code execution is provided; the attacker can only cause loss of service for that user.
Affected Systems
The vulnerability affects Apple Safari on iOS, iPadOS, macOS, and visionOS. Devices running versions earlier than Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, or visionOS 27 are at risk. Releases that include the fix are considered secure.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity. EPSS is less than 1 %, indicating a low exploitation probability. The vulnerability is not listed in CISA KEV. Exploitation requires a victim to view malicious content in Safari; no publicly available exploit or payload is reported. The overall risk is low, but affected users should patch as soon as an update is available.
OpenCVE Enrichment