The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.
CVSS Details
- CVSS 3.1 Base Score: 8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-webkitgtk4amazon-linux-ami-2-upgrade-webkitgtk4-develamazon-linux-ami-2-upgrade-webkitgtk4-jscamazon-linux-ami-2-upgrade-webkitgtk4-jsc-devel | May 20, 2026 | May 20, 2026 | |
| Apple Osx Webkit | apple-osx-upgrade-latest | May 15, 2025 | May 15, 2025 | |
| Apple Safari | apple-safari-upgrade-18_5apple-safari-windows-uninstall | May 13, 2025 | May 13, 2025 | |
| Debian | debian-upgrade-webkit2gtk | Mar 23, 2026 | Mar 23, 2026 | |
| Ubuntu | ubuntu-upgrade-webkit2gtk | Mar 31, 2026 | Mar 30, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub