Impact
The flaw in WebKitGTK causes memory corruption when an application processes maliciously crafted web content. The issue is classified under CWE‑119 and CWE‑120, indicating a buffer overflow or similar memory handling error. The resulting corruption can lead to application crashes or other unintended behavior, but the CVE description does not state that the flaw yields arbitrary code execution.
Affected Systems
Affected vendors include Apple and Red Hat. Apple products such as Safari, iOS, iPadOS, macOS Sequoia, tvOS, visionOS, and watchOS are impacted; the patch releases are Safari 18.6, iOS 18.6, iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, and watchOS 11.6. Red Hat Enterprise Linux 8 and 9, along with their extended service streams (RHEL AUS, RHEL E4S, RHEL EUS, RHEL TUS), are also affected because the CPE list references multiple RHEL releases that embed WebKitGTK.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score of 1 % suggests that real‑world exploitation is relatively uncommon, yet the vulnerability is listed in the CISA KEV catalog, confirming that active exploits have been observed. The likely attack vector is the delivery of malicious web content through a browser or an application that embeds WebKitGTK, which can remotely trigger the memory corruption.
OpenCVE Enrichment
EUVD