Impact
The vulnerability in WebKitGTK occurs when improperly handling maliciously crafted web content, allowing the disclosure of process memory. It is identified as a buffer handling issue (CWE-119) and a use‑after‑free error (CWE-416). The impact is a confidentiality breach, as data visible in process memory can be exposed to an unauthenticated attacker.
Affected Systems
The affected platforms are Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. All releases prior to Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6 are vulnerable. Upgrading to the listed versions or newer versions mitigates the flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of < 1% suggests a very low probability of exploitation at this time. The vulnerability is not included in the CISA KEV catalog, further indicating limited exploitation activity. Based on the description, the likely attack vector involves a user visiting malicious web content that exploits the memory handling flaw; the attacker does not need elevated privileges or sophisticated infrastructure. The absence of a high EPSS score does not eliminate risk, as the disclosure of process memory could reveal sensitive information.
OpenCVE Enrichment
Debian DSA