Impact
The vulnerability arises from improper memory handling in Safari, where maliciously crafted web content can trigger an unexpected crash. The crash disrupts the browser and any dependent services, resulting in a denial‑of‑service for the user. The defect is local and can be triggered solely by viewing crafted content; no privileged access is required to exploit it.
Affected Systems
Affected Apple devices run iOS, iPadOS, or macOS and are vulnerable if operating systems precede the patched releases. The fix is included in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, and macOS Tahoe 26.6.2. Devices that run older versions of these operating systems remain at risk.
Risk and Exploitability
The CVSS score is 4.3, the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is a malicious web page delivered by an attacker; the attacker merely needs the victim to view the crafted content in Safari. The lack of a public exploit suggests the likelihood of exploitation is uncertain but non‑zero, while the impact remains moderate to high due to the denial‑of‑service nature of the crash.
OpenCVE Enrichment