Impact
An integer overflow was identified in the processing of web content on several Apple platforms. When a user views maliciously crafted web content, the overflow can lead to memory corruption, potentially causing a system crash or facilitating other types of exploitation.
Affected Systems
The vulnerability affects Apple Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS. Specifically, Safari 26.6.1, iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27 include the fix. Users running earlier versions of these products remain vulnerable until they upgrade to a patched release.
Risk and Exploitability
The flaw scores 8.8 on CVSS, indicating a high severity. The EPSS score is < 1%, indicating a very low probability of exploitation in the wild. It is not included in the CISA KEV catalog. Attackers can trigger the integer overflow by delivering maliciously crafted web content to a vulnerable browser or application, potentially causing memory corruption and leading to denial of service or arbitrary code execution, depending on the attacker’s skill and system context. Because the flaw can be activated simply by browsing a malicious site, it is remotely exploitable without local privileges.
OpenCVE Enrichment