Impact
The vulnerability is caused by a flaw in memory handling when parsing maliciously crafted web content. The result is memory corruption that can crash the browser or enable more advanced exploits. Apple has addressed the issue with improved memory management; the fix is in Safari 26.6.1, iOS 18.7.10 and 26.6.1, iPadOS 18.7.10 and 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27. Until these patches are applied, the flaw remains in all affected Apple devices.
Affected Systems
Affected devices include all versions of Safari, iOS, iPadOS, and macOS prior to the patched releases listed above. Apple hardware running these operating systems or browsers is susceptible.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is less than 1%. Attackers would need to supply crafted web content to a user’s browser; if successful, the resulting memory corruption could cause application crashes or more advanced attacks if further leveraged.
OpenCVE Enrichment