Impact
A logic flaw in Apple’s state‑management system can be triggered by maliciously crafted web content, causing the affected process or application to terminate abruptly. The impact is a denial‑of‑service condition, as normal user activity may be interrupted and the user may need to restart the application or device.
Affected Systems
Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS in any release prior to build 27.x. The patch was introduced in Safari 27, iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27.
Risk and Exploitability
Exploitation requires delivery of tailored web content to a user’s device, typically by visiting a malicious website. The CVSS score of 6.5 indicates moderate risk from a severity point of view, while the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. With no known active exploitation, the overall risk is considered moderate, but the denial‑of‑service impact satisfies a DoS classification because it can disrupt user experience or system stability.
OpenCVE Enrichment
Debian DSA