Impact
A weakness in Safari’s state management allows maliciously crafted web content to cause Safari to crash unexpectedly. The flaw stems from improper handling of internal state when processing such content, leading to an abrupt termination of the browser. This crash results in a temporary denial of service, interrupting browsing sessions and potentially requiring a device restart before normal operation resumes. The vulnerability has been addressed in Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2.
Affected Systems
The vulnerability affects Apple devices running iOS versions prior to 26.6.1, iPadOS versions prior to 26.6.1, and macOS Tahoe versions prior to 26.6.2. All versions of Safari bundled with these operating systems are impacted.
Risk and Exploitability
The vulnerability is exploitable via any web page that includes specially crafted content. The risk is a local denial of service that can be triggered remotely by visiting a malicious site; the CVSS score of 4.3 indicates low severity, and the EPSS score of <1% suggests that exploitation is unlikely. The issue is not listed in CISA’s KEV catalog.
OpenCVE Enrichment