Impact
A state management flaw in Safari can be triggered when the browser parses maliciously crafted web content, causing the application to crash unexpectedly. This results in a temporary denial of service for the user until Safari or the device is restarted. The issue is fixed by updated state management in newer releases.
Affected Systems
The vulnerability affects Apple Safari and web browsing components on Apple iOS, iPadOS, macOS, and visionOS devices that are running versions prior to the security patches. Specifically, Safari releases before 26.6.1, iOS and iPadOS releases before 18.7.10 and 26.6.1, macOS Tahoe before 26.6.2, and visionOS before 27 are impacted. All earlier builds are also susceptible.
Risk and Exploitability
The CVSS base score of 4.3 classifies the flaw as low severity, while the EPSS score of less than 1 % indicates that exploitation is unlikely in the near term. The issue is not catalogued in CISA's KEV list, and no active exploits are publicly reported. If an attacker hosts a web page containing crafted content that Safari loads, the application may crash, causing a local denial‑of‑service until the user restarts it or the system reboots.
OpenCVE Enrichment