Impact
This vulnerability originates from a flaw in WebKitGTK state management that causes Safari to crash when it processes maliciously crafted web content. The resulting crash terminates the browser process, causing a local loss of service. Because the crash is confined to the browser, attackers cannot gain elevated privileges or compromise the underlying operating system, and there is no evidence of data leakage or persistence. The impact is strictly a denial‑of‑service condition that affects end‑user browsing in Safari.
Affected Systems
The affected products are Apple Safari, and all Apple platforms that include Safari: iOS, iPadOS, macOS Tahoe, and visionOS. The problem was addressed in Safari 26.6.1, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 27. Devices running earlier releases of any of these products are considered vulnerable until the corresponding update is installed. Versions newer than the listed releases are assumed to contain the fix.
Risk and Exploitability
The EPSS score of < 1 % indicates a very low likelihood of public exploitation, and the vulnerability is not listed in the CISA KEV catalog for known exploited vulnerabilities. The likely attack vector is a user visiting maliciously crafted web content in Safari. The CVSS score of 4.3 categorizes the flaw as moderate severity, reflecting the restriction to a browser crash without privilege escalation or data compromise.
OpenCVE Enrichment