Impact
Apple has indicated that a flaw in web content handling in Safari can lead to an unexpected crash when processing maliciously crafted pages. The crash removes the ability to browse, effectively creating a denial‑of‑service condition for the user. This is limited to the Safari browser and, by extension, any browsing activity performed on the affected systems.
Affected Systems
The affected products are Apple iOS, iPadOS, and macOS Tahoe. The vulnerability is fixed in iOS 18.7.10, iPadOS 18.7.10, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2; earlier releases prior to these updates are presumed vulnerable, although exact minimum affected versions are not specified. All newer releases beyond these specified fixes are considered protected.
Risk and Exploitability
The EPSS score is <1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog, so public exploitation data is limited. The attack vector is inferred to be a web‑based one, requiring a user to load or view malicious content in Safari. The impact is a local denial of service, and while it does not grant broader system compromise, repeated exploitation can degrade user experience and expose users to additional threats. The CVSS score of 4.3 categorizes it as moderate.
OpenCVE Enrichment