Processing maliciously crafted web content may lead to an unexpected process termination
A logic issue was addressed with improved state management.
WebKit CVEs from Apple's Safari security release pages, cross-referenced to the public WebKit fix commit and, when covered, to the WebKit Weekly analysis of that fix.
Matching is by WebKit Bugzilla number — Apple exposes it on every WebKit CVE
entry, and WebKit commits include the same ID as a
bugs.webkit.org/show_bug.cgi?id=… reference. Unmatched CVEs are
shown too: they usually mean the fix commit is still under Bugzilla embargo.
Processing maliciously crafted web content may lead to an unexpected process termination
A logic issue was addressed with improved state management.
Processing maliciously crafted web content may disclose sensitive user information
A permissions issue was addressed by removing the vulnerable code.
Opening a maliciously crafted webarchive file may lead to universal cross-site scripting
A logic issue was addressed with improved state management.
Processing maliciously crafted web content may lead to an unexpected Safari crash
An out-of-bounds access issue was addressed with improved bounds checking.
Processing maliciously crafted web content may lead to an unexpected Safari crash
The issue was addressed with improved memory handling.
Processing maliciously crafted web content may lead to memory corruption
The issue was addressed with improved memory handling.
Processing maliciously crafted web content may lead to an unexpected Safari crash
A memory corruption vulnerability was addressed with improved locking.
Processing maliciously crafted web content may lead to an unexpected Safari crash
The issue was addressed with improved input validation.
Processing maliciously crafted web content may lead to an unexpected Safari crash
This issue was addressed through improved state management.
Processing maliciously crafted web content may lead to an unexpected process crash
A use-after-free issue was addressed with improved memory management.
Processing maliciously crafted web content may lead to an unexpected Safari crash
The issue was addressed with improved checks.
Processing maliciously crafted web content may lead to an unexpected Safari crash
A memory corruption issue was addressed with improved state management.
Processing maliciously crafted web content may lead to memory corruption
A memory corruption issue was addressed with improved memory handling.
Processing maliciously crafted web content may lead to an unexpected process termination
A use-after-free issue was addressed with improved memory management.
Websites may know if the user has visited a given link
This issue was addressed with improved checks.
Visiting a website that frames malicious content may lead to UI spoofing
The issue was addressed with improved UI.
Maliciously crafted web content may violate iframe sandboxing policy
A permissions issue was addressed with improved validation.
Processing maliciously crafted web content may lead to an unexpected Safari crash
A use-after-free issue was addressed with improved memory management.
Processing maliciously crafted web content may lead to an unexpected Safari crash
A memory corruption issue was addressed with improved state management.
Visiting a website may lead to an app denial-of-service
This issue was addressed through improved state management.
An app may be able to read files outside of its sandbox
An access issue was addressed with improved access restrictions.
Processing maliciously crafted web content may disclose sensitive user information
A cross-origin issue was addressed with improved tracking of security origins.
A malicious website may exfiltrate data cross-origin
The issue was addressed with improved checks.
Processing maliciously crafted web content may lead to an unexpected process crash
A use-after-free issue was addressed with improved memory management.
Processing maliciously crafted web content may disclose sensitive user information
A path handling issue was addressed with improved validation.
Processing maliciously crafted web content may lead to memory corruption
A use-after-free issue was addressed with improved memory management.
Processing maliciously crafted web content may lead to an unexpected Safari crash
A use-after-free issue was addressed with improved memory management.
A malicious website may be able to process restricted web content outside the sandbox
The issue was addressed with improved input validation.
Processing maliciously crafted web content may lead to an unexpected process crash
The issue was addressed with improved memory handling.
Processing maliciously crafted web content may lead to an unexpected Safari crash
The issue was addressed with improved memory handling.
Processing maliciously crafted web content may lead to an unexpected Safari crash
An out-of-bounds access issue was addressed with improved bounds checking.
Processing maliciously crafted web content may result in the disclosure of process memory
The issue was addressed with improved memory handling.
Visiting a website may leak sensitive data
A permissions issue was addressed with additional restrictions.
A malicious website may exfiltrate data cross-origin
The issue was addressed with improved input validation.
Processing maliciously crafted web content may lead to an unexpected process crash
A memory corruption issue was addressed with improved memory handling.
Processing maliciously crafted web content may lead to memory corruption
A type confusion issue was addressed with improved checks.
A malicious website may be able to process restricted web content outside the sandbox
The issue was addressed with improved checks.
Processing maliciously crafted web content may lead to an unexpected Safari crash
An out-of-bounds write issue was addressed with improved input validation.
Processing maliciously crafted web content may prevent Content Security Policy from being enforced
A validation issue was addressed with improved logic.
Processing maliciously crafted web content may prevent Content Security Policy from being enforced
The issue was addressed with improved input validation.
Processing maliciously crafted web content may disclose sensitive user information
This issue was addressed with improved access restrictions.
Processing maliciously crafted web content may lead to an unexpected Safari crash
The issue was addressed with improved memory handling.
Processing maliciously crafted web content may lead to an unexpected process crash
The issue was addressed with improved memory handling.
Processing maliciously crafted web content may lead to an unexpected process crash
A use-after-free issue was addressed with improved memory management.
An app may be able to access sensitive user data
This issue was addressed with improved data protection.
Processing maliciously crafted web content may lead to an unexpected process crash
The issue was addressed with improved input validation.
Processing maliciously crafted web content may lead to an unexpected Safari crash
A use-after-free issue was addressed with improved memory management.
A malicious iframe may use another website’s download settings
The issue was addressed with improved UI handling.
Processing maliciously crafted web content may bypass Content Security Policy
A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts.