Impact
The vulnerability arises from insufficient memory handling when a browser parses maliciously crafted web content on Apple devices. The flaw can result in memory corruption, which may destabilize the system or enable more severe exploitation. Apple has addressed the issue with improved memory handling, and the vulnerability is fixed in Safari 26.6.1, iOS 18.7.10 and 26.6.1, iPadOS 18.7.10 and 26.6.1, and macOS Tahoe 26.6.2.
Affected Systems
Affected devices include all versions of Safari, iOS, iPadOS, and macOS prior to the patched releases listed above. Apple hardware running these operating systems or browsers is susceptible.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is less than 1%, implying a low likelihood of exploitation. The vulnerability is not catalogued in CISA KEV. Attackers would need to supply crafted web content to a user’s browser; if successful, the resulting memory corruption could cause application crashes or more advanced attacks if further leveraged.
OpenCVE Enrichment