Impact
The vulnerability arises from improper memory handling while processing maliciously crafted web content on Apple operating systems. The flaw can lead to memory corruption, which may enable arbitrary code execution or cause a denial of service. This weakness represents unsafe buffer manipulation within the web content parsing subsystem.
Affected Systems
Affected versions include Apple iOS 18.7.10, iOS 26.6.1, Apple iPadOS 18.7.10, iPadOS 26.6.1, and Apple macOS Tahoe 26.6.2 on Apple hardware.
Risk and Exploitability
No publicly available CVSS or EPSS scores are attached to this entry, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require an attacker to deliver malicious web content that a user loads in a browser, after which the memory corruption could lead to arbitrary code execution or a crash. The lack of exploitation data suggests that while the technical impact is severe, the likelihood of active exploitation remains uncertain but potentially high if discovered by adversaries.
OpenCVE Enrichment