Impact
A use‑after‑free flaw was uncovered in WebKitGTK, a rendering engine used by Apple’s Safari and various system web views. The vulnerability stems from insufficient memory‑management safeguards, allowing maliciously crafted web content to reference a freed object and corrupt process memory. While the updated code blocks this issue in Safari 26.5.2 and several operating system releases—iOS 18.7.10, iPadOS 18.7.10, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6—unpatched devices remain susceptible. An attacker could abuse the memory‑corruption condition to alter program state or potentially execute arbitrary code, affecting confidentiality, integrity, or availability.
Affected Systems
Apple products – Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS – are affected by releases prior to Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The EPSS score of 0.26% indicates a very low but nonzero exploitation probability. The CVSS score of 8.8 demonstrates high severity, emphasizing the risk of memory corruption that could be leveraged for privilege escalation or remote code execution if an attacker can inject or drive crafted content through Safari or system web components. This vulnerability is not listed in the CISA KEV catalog, reducing the likelihood that known exploit payloads are actively used. The likely attack vector involves visiting malicious web pages or loading infected resources in affected Apple browsers or web views.
OpenCVE Enrichment
Debian DSA