Impact
A weakness in Safari’s state management allows an attacker to cause the browser to crash when it processes maliciously crafted web content. The crash results in a denial of service that can temporarily interrupt web browsing, and may require a device restart before normal operation resumes.
Affected Systems
The vulnerability affects Apple devices running iOS versions prior to 26.6.1, iPadOS versions prior to 26.6.1, and macOS Tahoe versions prior to 26.6.2. All versions of Safari bundled with these operating systems are impacted.
Risk and Exploitability
The vulnerability is exploitable via any web page that includes specially crafted content. The risk is a local denial of service that can be triggered remotely by visiting a malicious site; the excerpt does not provide a CVSS score, and EPSS data is unavailable, so the quantitative risk level cannot be precisely assessed. The issue is not listed in CISA’s KEV catalog.
OpenCVE Enrichment