Description
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Published: 2025-05-12
Score: 4.3 Medium
EPSS: 1.1% Low
KEV: No
Impact: Denial of Service (Crash)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a type confusion flaw in WebKitGTK that can cause Safari to crash when it processes specially crafted web content. This type confusion, catalogued as CWE‑843, means that the application interprets data of one type as another, leading to an unhandled exception. The crash removes service availability for the user, potentially resulting in a denial of service. No arbitrary code execution or information disclosure is reported in the description, so the primary risk is service interruption.

Affected Systems

Apple products with Safari and other web browsers on iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The flaw persists in releases before Safari 18.5, iOS 18.5, iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, and watchOS 11.5. The vulnerability is also present in WebKitGTK deployments on Red‑Hat Enterprise Linux 8, 9, and several RHEL 8.x and RHEL 9.x builds. Users on any of these operating systems running Safari or WebKitGTK should be aware that malicious pages could trigger a crash.

Risk and Exploitability

The CVSS score of 4.3 classifies the flaw as moderate, and the EPSS score of 1 % indicates a low likelihood of widespread exploitation. Because the issue only manifests when maliciously crafted content is rendered, the attack vector is effectively local to the user’s browser session or a phishing page. The vulnerability is not listed in the CISA KEV catalog, so no known field‑operational exploitation has been reported.

Generated by OpenCVE AI on April 28, 2026 at 01:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all affected Apple operating systems to the latest releases: Safari 18.5, iOS 18.5, iPadOS 18.5, iPadOS 17.7.7, macOS 15.5, tvOS 18.5, visionOS 2.5, or watchOS 11.5.
  • On Linux platforms, install the patched WebKitGTK packages that provide the fix for the identified type confusion, enabling the security update from the distribution vendor.
  • If updating is not immediately possible, avoid visiting untrusted web pages and consider disabling or sandboxing WebKitGTK‑based browsers until a patch is available.

Generated by OpenCVE AI on April 28, 2026 at 01:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4218-1 webkit2gtk security update
Debian DSA Debian DSA DSA-5937-1 webkit2gtk security update
EUVD EUVD EUVD-2025-14628 A type confusion issue was addressed with improved state handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Ubuntu USN Ubuntu USN USN-7566-1 WebKitGTK vulnerabilities
History

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A type confusion issue was addressed with improved state handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to an unexpected Safari crash. A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Mon, 03 Nov 2025 20:30:00 +0000


Mon, 07 Jul 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Els
CPEs cpe:/o:redhat:rhel_els:7
Vendors & Products Redhat rhel Els

Tue, 27 May 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ipados
Apple iphone Os
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple ipados
Apple iphone Os
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos

Fri, 16 May 2025 02:30:00 +0000

Type Values Removed Values Added
Title webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
First Time appeared Redhat
Redhat enterprise Linux
Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Tus
CPEs cpe:/a:redhat:enterprise_linux:8
cpe:/a:redhat:enterprise_linux:9
cpe:/a:redhat:rhel_aus:8.2
cpe:/a:redhat:rhel_aus:8.4
cpe:/a:redhat:rhel_aus:8.6
cpe:/a:redhat:rhel_e4s:8.4
cpe:/a:redhat:rhel_e4s:8.6
cpe:/a:redhat:rhel_e4s:9.0
cpe:/a:redhat:rhel_tus:8.4
cpe:/a:redhat:rhel_tus:8.6
Vendors & Products Redhat
Redhat enterprise Linux
Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Tus
References
Metrics threat_severity

None

threat_severity

Important


Tue, 13 May 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-843
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 12 May 2025 21:45:00 +0000

Type Values Removed Values Added
Description A type confusion issue was addressed with improved state handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References

Subscriptions

Apple Ipados Iphone Os Macos Safari Tvos Visionos Watchos
Redhat Enterprise Linux Rhel Aus Rhel E4s Rhel Els Rhel Tus
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:21:31.850Z

Reserved: 2025-03-27T16:13:58.316Z

Link: CVE-2025-31206

cve-icon Vulnrichment

Updated: 2025-11-03T19:48:46.141Z

cve-icon NVD

Status : Modified

Published: 2025-05-12T22:15:21.717

Modified: 2026-04-02T19:19:47.530

Link: CVE-2025-31206

cve-icon Redhat

Severity : Important

Publid Date: 2025-05-15T00:00:00Z

Links: CVE-2025-31206 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T01:45:18Z

Weaknesses