Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10.2 on Windows, Apple Safari, and Google Chrome before 6.0.472.59, allows remote attackers to execute arbitrary code or cause a denial of service via vectors related to SVG styles, the DOM tree, and error messages.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Jun 25, 2026 | Jan 5, 2024 |
| Apple Safari | — | Uninstall Apple Safari on WindowsUpgrade to Apple Safari version 5.0.4 | Jan 5, 2012 | Sep 24, 2010 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Sep 17, 2012 | Sep 24, 2010 |
| Suse | — | Upgrade libwebkit-1_0-2-32bitUpgrade libwebkit-langUpgrade webkit-jscUpgrade libwebkit-develUpgrade libwebkit-1_0-2 | Feb 17, 2015 | Sep 24, 2010 |
| Ubuntu | — | Upgrade libwebkit-1.0-2 | Nov 8, 2024 | Sep 24, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub