Impact
A memory handling flaw in WebKitGTK can cause a denial of service when rendering web content. The weakness involves excessive memory allocation, as indicated by CWE-770, and an input validation failure, CWE-79, which together allow an attacker to crash the target process. The impact is a crash of the WebKit component, potentially disrupting user applications that rely on web rendering, but no direct data compromise is described.
Affected Systems
Apple Safari, iOS, iPadOS, macOS Sequoia, tvOS, visionOS, and watchOS are affected. The vulnerability is fixed in Safari 18.3, iOS 18.3, iPadOS 18.3, macOS 15.3, tvOS 18.3, visionOS 2.3, and watchOS 11.3. Red Hat Enterprise Linux 8, 9 and RHEL ELS 7 are also listed as affected via the CPEs but the description does not specify impact on those platforms.
Risk and Exploitability
The CVSS score of 6.5 classifies this as a moderate severity vulnerability. The EPSS score of less than 1% indicates a very low probability of exploitation at the time of this analysis, and it is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote—an attacker could embed malicious content within a web page that a user or application renders, potentially triggering the memory overflow and causing a crash. No specific prerequisites beyond the ability to deliver such content are mentioned in the entry.
OpenCVE Enrichment
Debian DLA
Debian DSA
EUVD
Ubuntu USN