Apple Security Updates

WebKit CVEs from Apple's Safari security release pages, cross-referenced to the public WebKit fix commit and, when covered, to the WebKit Weekly analysis of that fix.

Matching is by WebKit Bugzilla number — Apple exposes it on every WebKit CVE entry, and WebKit commits include the same ID as a bugs.webkit.org/show_bug.cgi?id=… reference. Unmatched CVEs are shown too: they usually mean the fix commit is still under Bugzilla embargo.

20 Safari releases 130 WebKit CVEs 102 matched to a commit 13 covered in a report 15 mentioned in a report
Safari 26.6 July 27, 2026 · 7 WebKit CVEs ·1 covered
CVE-2026-64730

Visiting a website that frames malicious content may lead to UI spoofing

The issue was addressed with improved UI.

Bugzilla 311660 Fix not yet public
Credit: Kagami Rosylight of Mozilla
CVE-2026-64728

Maliciously crafted web content may violate iframe sandboxing policy

A permissions issue was addressed with improved validation.

Bugzilla 313220 Fix not yet public
Credit: an anonymous researcher
CVE-2026-64783

Processing maliciously crafted web content may lead to an unexpected Safari crash

A use-after-free issue was addressed with improved memory management.

Bugzilla 313521 Fix not yet public
Credit: 杉山 壮太, lattice, Behzad Najjarpour Jabbari (@_G4ru_), Junyeong Lee, Mooth.ai, OGINOME Tomohito, Using GLM From Z.AI, Gia Bui (@yabeow) from Calif.io
CVE-2026-43804

Visiting a website may lead to an app denial-of-service

This issue was addressed through improved state management.

Bugzilla 316816 Fix not yet public
Credit: Heiko Kiesel of SEEMOO, TU Darmstadt
Safari 26.5.2 June 29, 2026 · 17 WebKit CVEs ·1 covered
CVE-2026-43700

Processing maliciously crafted web content may disclose sensitive user information

A cross-origin issue was addressed with improved tracking of security origins.

Credit: Vitaly Simonovich, Christian Meurer Xavier
CVE-2026-43735

A malicious website may exfiltrate data cross-origin

The issue was addressed with improved checks.

Bugzilla 313357 Fix not yet public
Credit: Gurpreet Shergill, Merrick Hare, Drinor Selmanaj (Sentry), Khai Tran, John Lussier, Rhyru9, Kwak Kiyong, Song Nuri
CVE-2026-43734

Processing maliciously crafted web content may lead to an unexpected process crash

A use-after-free issue was addressed with improved memory management.

Bugzilla 313693 Fix not yet public
Credit: Jonathan Alush-Aben
CVE-2026-43732

Processing maliciously crafted web content may disclose sensitive user information

A path handling issue was addressed with improved validation.

Credit: Nan Wang (@eternalsakura13)
CVE-2026-43727

Processing maliciously crafted web content may lead to an unexpected Safari crash

A use-after-free issue was addressed with improved memory management.

Credit: Tommy DeVoss from Braze Security Team (@thedawgyg), Gia Bui (@yabeow) from Calif.io, Gurpreet Shergill
CVE-2026-43663

Processing maliciously crafted web content may lead to an unexpected process crash

The issue was addressed with improved memory handling.

Credit: stratan (@5tratan) of Almamater Technologies, Soyeon Park, Amy Burnett, Khai Tran, sherkito, Kota Toda, HexRabbit (@h3xr4bb1t) and NiNi (@terrynini38514) of DEVCORE Research Team, Using GLM From Z.AI, Tristan Madani (@TristanInSec) from Talence Security, Brian Carpenter
CVE-2026-43716

Processing maliciously crafted web content may lead to an unexpected Safari crash

The issue was addressed with improved memory handling.

Credit: Maher Azzouzi, Tuan and Duc from Calif.io, OpenAI Codex Security - Amy Burnett, Evan Lambert
CVE-2026-43676

Processing maliciously crafted web content may lead to an unexpected Safari crash

An out-of-bounds access issue was addressed with improved bounds checking.

Bugzilla 317231 Fix not yet public
Credit: Mateusz Krzywicki (iVerify.io), dr3dd, Tommy DeVoss from Braze Security Team (@thedawgyg)
CVE-2026-43740

Processing maliciously crafted web content may result in the disclosure of process memory

The issue was addressed with improved memory handling.

Credit: Nathaniel Oh (@calysteon), Arni Hardarson
CVE-2026-43707

Processing maliciously crafted web content may lead to an unexpected process crash

A memory corruption issue was addressed with improved memory handling.

Bugzilla 315951 Fix not yet public
Credit: stratan (@5tratan) of Almamater Technologies, OpenAI Codex Security - Amy Burnett
CVE-2026-43701

A malicious website may be able to process restricted web content outside the sandbox

The issue was addressed with improved checks.

Credit: Aaron Grattafiori - NVIDIA AI Red Team
CVE-2026-43745

Processing maliciously crafted web content may lead to an unexpected Safari crash

An out-of-bounds write issue was addressed with improved input validation.

Credit: OpenAI Codex Security - Amy Burnett, Khai Tran
Safari 26.5 May 13, 2026 · 10 WebKit CVEs ·3 covered
CVE-2026-43660

Processing maliciously crafted web content may prevent Content Security Policy from being enforced

A validation issue was addressed with improved logic.

Credit: Cantina
CVE-2026-28905

Processing maliciously crafted web content may lead to an unexpected process crash

The issue was addressed with improved memory handling.

Credit: Yuhao Hu, Yuanming Lai, Chenggang Wu, and Zhe Wang
CVE-2026-28883

Processing maliciously crafted web content may lead to an unexpected process crash

A use-after-free issue was addressed with improved memory management.

Bugzilla 313939 Fix not yet public
Credit: kwak kiyong / kakaogames
CVE-2026-28917

Processing maliciously crafted web content may lead to an unexpected process crash

The issue was addressed with improved input validation.

Bugzilla 310527 Fix not yet public
Credit: Vitaly Simonovich
Safari 26.4 March 24, 2026 · 6 WebKit CVEs ·6 covered
Safari 26.3 February 11, 2026 · 4 WebKit CVEs ·2 covered
CVE-2026-20608

Processing maliciously crafted web content may lead to an unexpected process crash

This issue was addressed through improved state management.

Credit: HanQing from TSDubhe and Nan Wang (@eternalsakura13)
Safari 26.2 December 12, 2025 · 9 WebKit CVEs
CVE-2025-46282

An app may be able to access sensitive user data

The issue was addressed with additional permissions checks.

Credit: Wojciech Regula of SecuRing (wojciechregula.blog)
CVE-2025-43541

Processing maliciously crafted web content may lead to an unexpected Safari crash

A type confusion issue was addressed with improved state handling.

Credit: Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative
CVE-2025-43536

Processing maliciously crafted web content may lead to an unexpected process crash

A use-after-free issue was addressed with improved memory management.

Credit: Nan Wang (@eternalsakura13)
CVE-2025-43535

Processing maliciously crafted web content may lead to an unexpected process crash

The issue was addressed with improved memory handling.

Credit: Google Big Sleep, Nan Wang (@eternalsakura13)
CVE-2025-43501

Processing maliciously crafted web content may lead to an unexpected process crash

A buffer overflow issue was addressed with improved memory handling.

Credit: Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative
CVE-2025-43529

Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.

A use-after-free issue was addressed with improved memory management.

Credit: Google Threat Analysis Group
CVE-2025-14174

Processing maliciously crafted web content may lead to memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-43529 was also issued in response to this report.

A memory corruption issue was addressed with improved validation.

Bugzilla 303614 Fix not yet public
Credit: Apple and Google Threat Analysis Group
CVE-2025-46299

Processing maliciously crafted web content may disclose internal states of the app

A memory initialization issue was addressed with improved memory handling.

Bugzilla 299518 Fix not yet public
Credit: Google Big Sleep
Safari 26.1 November 3, 2025 · 10 WebKit CVEs
CVE-2025-43458

Processing maliciously crafted web content may lead to an unexpected process crash

This issue was addressed through improved state management.

Bugzilla 296693 Fix not yet public
Credit: Phil Beauvoir
CVE-2025-43443

Processing maliciously crafted web content may lead to an unexpected process crash

This issue was addressed with improved checks.

Bugzilla 299843 Fix not yet public
Credit: an anonymous researcher
CVE-2025-43440

Processing maliciously crafted web content may lead to an unexpected process crash

This issue was addressed with improved checks

Credit: Nan Wang (@eternalsakura13)
CVE-2025-43438

Processing maliciously crafted web content may lead to an unexpected Safari crash

A use-after-free issue was addressed with improved memory management.

Credit: rheza (@ginggilBesel), shandikri working with Trend Micro Zero Day Initiative
CVE-2025-43433

Processing maliciously crafted web content may lead to memory corruption

The issue was addressed with improved memory handling.

Bugzilla 298093 Fix not yet public
Credit: Google Big Sleep
CVE-2025-43432

Processing maliciously crafted web content may lead to an unexpected process crash

A use-after-free issue was addressed with improved memory management.

Credit: Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative
CVE-2025-43429

Processing maliciously crafted web content may lead to an unexpected process crash

A buffer overflow was addressed with improved bounds checking.

Credit: Google Big Sleep
CVE-2025-43421

Processing maliciously crafted web content may lead to an unexpected process crash

Multiple issues were addressed by disabling array allocation sinking.

Bugzilla 300718 Fix not yet public
Credit: Nan Wang (@eternalsakura13)
Safari 26 September 15, 2025 · 6 WebKit CVEs
CVE-2025-43356

A website may be able to access sensor information without user consent

The issue was addressed with improved handling of caches.

Credit: Jaydev Ahire
CVE-2025-43272

Processing maliciously crafted web content may lead to an unexpected Safari crash

The issue was addressed with improved memory handling.

Credit: Big Bear
CVE-2025-43343

Processing maliciously crafted web content may lead to an unexpected process crash

The issue was addressed with improved memory handling.

Credit: an anonymous researcher
CVE-2025-43342

Processing maliciously crafted web content may lead to an unexpected process crash

A correctness issue was addressed with improved checks.

Credit: an anonymous researcher
CVE-2025-43419

Processing maliciously crafted web content may lead to memory corruption

The issue was addressed with improved memory handling.

Credit: Ignacio Sanmillan (@ulexec)
CVE-2025-43376

A remote attacker may be able to view leaked DNS queries with Private Relay turned on

A logic issue was addressed with improved state management.

Credit: Mike Cardwell of grepular.com, Bob Lord
Safari 18.6 July 30, 2025 · 10 WebKit CVEs
CVE-2025-43229

Processing maliciously crafted web content may lead to universal cross site scripting

This issue was addressed through improved state management.

Credit: Martin Bajanik of Fingerprint, Ammar Askar
CVE-2025-43227

Processing maliciously crafted web content may disclose sensitive user information

This issue was addressed through improved state management.

Credit: Gilad Moav, Yehuda Afek, Anat Bremler-Barr, and Amit Klein
CVE-2025-31278

Processing maliciously crafted web content may lead to memory corruption

The issue was addressed with improved memory handling.

Credit: Yuhao Hu, Yan Kang, Chenggang Wu, and Xiaojie Wei
CVE-2025-43240

A download's origin may be incorrectly associated

A logic issue was addressed with improved checks.

Credit: Syarif Muhammad Sajjad
CVE-2025-43214

Processing maliciously crafted web content may lead to an unexpected Safari crash

The issue was addressed with improved memory handling.

Credit: shandikri working with Trend Micro Zero Day Initiative, Google V8 Security Team
CVE-2025-43211

Processing web content may lead to a denial-of-service

The issue was addressed with improved memory handling.

Credit: Yuhao Hu, Yan Kang, Chenggang Wu, and Xiaojie Wei
CVE-2025-43265

Processing maliciously crafted web content may disclose internal states of the app

An out-of-bounds read was addressed with improved input validation.

Credit: HexRabbit (@h3xr4bb1t) from DEVCORE Research Team
CVE-2025-43216

Processing maliciously crafted web content may lead to an unexpected Safari crash

A use-after-free issue was addressed with improved memory management.

Credit: Ignacio Sanmillan (@ulexec)
CVE-2025-6558

Processing maliciously crafted web content may lead to an unexpected Safari crash

This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at

Bugzilla 296459 Fix not yet public
Credit: Clément Lecigne and Vlad Stolyarov of Google's Threat Analysis Group
Safari 18.5 May 12, 2025 · 8 WebKit CVEs
CVE-2025-24213

A type confusion issue could lead to memory corruption

This issue was addressed with improved handling of floats.

Bugzilla 286694 Fix not yet public
Credit: Google V8 Security Team
CVE-2025-31223

Processing maliciously crafted web content may lead to memory corruption

The issue was addressed with improved checks.

Credit: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs
CVE-2025-24223

Processing maliciously crafted web content may lead to memory corruption

The issue was addressed with improved memory handling.

Bugzilla 287577 Fix not yet public
Credit: rheza (@ginggilBesel), Edouard Bochin (@le_douds) and Tao Yan (@Ga1ois) of Palo Alto Networks
CVE-2025-31217

Processing maliciously crafted web content may lead to an unexpected Safari crash

The issue was addressed with improved input validation.

Credit: Ignacio Sanmillan (@ulexec)
CVE-2025-31215

Processing maliciously crafted web content may lead to an unexpected process crash

The issue was addressed with improved checks.

Credit: Jiming Wang and Jikai Ren
CVE-2025-31206

Processing maliciously crafted web content may lead to an unexpected Safari crash

A type confusion issue was addressed with improved state handling.

Credit: Yuhao Hu, Yan Kang, Chenggang Wu, Xiaojie Wei
CVE-2025-31205

A malicious website may exfiltrate data cross-origin

The issue was addressed with improved checks.

Credit: Ivan Fratric of Google Project Zero
CVE-2025-31257

Processing maliciously crafted web content may lead to an unexpected Safari crash

This issue was addressed with improved memory handling.

Credit: Juergen Schmied of Lynck GmbH
Safari 18.4 March 31, 2025 · 5 WebKit CVEs
CVE-2025-24264

Processing maliciously crafted web content may lead to an unexpected Safari crash

The issue was addressed with improved memory handling.

Credit: Gary Kwong, and an anonymous researcher
CVE-2025-24209

Processing maliciously crafted web content may lead to an unexpected process crash

A buffer overflow issue was addressed with improved memory handling.

Credit: Francisco Alonso (@revskills), and an anonymous researcher
CVE-2025-24208

Loading a malicious iframe may lead to a cross-site scripting attack

A permissions issue was addressed with additional restrictions.

Credit: Muhammad Zaid Ghifari (Mr.ZheeV) and Kalimantan Utara
CVE-2025-30427

Processing maliciously crafted web content may lead to an unexpected Safari crash

A use-after-free issue was addressed with improved memory management.

Credit: rheza (@ginggilBesel)
CVE-2025-30425

A malicious website may be able to track users in Safari private browsing mode

This issue was addressed through improved state management.

Credit: an anonymous researcher
Safari 18.3.1 March 11, 2025 · 1 WebKit CVE
CVE-2025-24201

Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.)

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions.

Credit: Apple
Safari 18.3 January 27, 2025 · 4 WebKit CVEs
CVE-2025-24189

Processing maliciously crafted web content may lead to memory corruption

The issue was addressed with improved checks.

Credit: an anonymous researcher
CVE-2025-24143

A maliciously crafted webpage may be able to fingerprint the user

The issue was addressed with improved access restrictions to the file system.

Credit: an anonymous researcher
CVE-2025-24158

Processing web content may lead to a denial-of-service

The issue was addressed with improved memory handling.

Credit: Q1IQ (@q1iqF) of NUS CuriOSity and P1umer (@p1umer) of Imperial Global Singapore
CVE-2025-24162

Processing maliciously crafted web content may lead to an unexpected process crash

This issue was addressed through improved state management.

Credit: linjy of HKUS3Lab and chluo of WHUSecLab
Safari 18.2 December 11, 2024 · 4 WebKit CVEs
CVE-2024-54479

Processing maliciously crafted web content may lead to an unexpected process crash

The issue was addressed with improved checks.

Credit: Seunghyun Lee
CVE-2024-54508

Processing maliciously crafted web content may lead to an unexpected process crash

The issue was addressed with improved memory handling.

Credit: linjy of HKUS3Lab and chluo of WHUSecLab, Xiangwei Zhang of Tencent Security YUNDING LAB
CVE-2024-54505

Processing maliciously crafted web content may lead to memory corruption

A type confusion issue was addressed with improved memory handling.

Credit: Gary Kwong
CVE-2024-54534

Processing maliciously crafted web content may lead to memory corruption

The issue was addressed with improved memory handling.

Credit: Tashita Software Security
Safari 18.1.1 November 19, 2024 · 1 WebKit CVE
CVE-2024-44309

Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

A cookie management issue was addressed with improved state management.

Credit: Clément Lecigne and Benoît Sevens of Google's Threat Analysis Group
Safari 18.1 October 29, 2024 · 3 WebKit CVEs
CVE-2024-44212

Cookies belonging to one origin may be sent to another origin

A cookie management issue was addressed with improved state management.

Credit: Wojciech Regula of SecuRing (
CVE-2024-44296

Processing maliciously crafted web content may prevent Content Security Policy from being enforced

The issue was addressed with improved checks.

Credit: Narendra Bhati, Manager of Cyber Security at Suma Soft Pvt. Ltd, Pune (India)
CVE-2024-44244

Processing maliciously crafted web content may lead to an unexpected process crash

A memory corruption issue was addressed with improved input validation.

Bugzilla 279780 Fix not yet public
Credit: an anonymous researcher, Q1IQ (@q1iqF) and P1umer (@p1umer)
Safari 18 September 16, 2024 · 5 WebKit CVEs
CVE-2024-54467

A malicious website may exfiltrate data cross-origin

A cookie management issue was addressed with improved state management.

Bugzilla 287874 Fix not yet public
Credit: Narendra Bhati, Manager of Cyber Security At Suma Soft Pvt. Ltd, Pune (India)
CVE-2024-44192

Processing maliciously crafted web content may lead to an unexpected process crash

The issue was addressed with improved checks.

Credit: Tashita Software Security
CVE-2024-40866

Visiting a malicious website may lead to address bar spoofing

The issue was addressed with improved UI.

Bugzilla 279451 Fix not yet public
Credit: Hafiizh and YoKo Kho (@yokoacc) of HakTrak
CVE-2024-44187

A malicious website may exfiltrate data cross-origin

A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins.

Bugzilla 279452 Fix not yet public
Credit: Narendra Bhati, Manager of Cyber Security at Suma Soft Pvt. Ltd, Pune (India)
CVE-2024-40857

Processing maliciously crafted web content may lead to universal cross site scripting

This issue was addressed through improved state management.

Credit: Ron Masas
Safari 17.6 July 29, 2024 · 8 WebKit CVEs
CVE-2024-40776

Processing maliciously crafted web content may lead to an unexpected process crash

A use-after-free issue was addressed with improved memory management.

Credit: Huang Xilin of Ant Group Light-Year Security Lab
CVE-2024-40779

Processing maliciously crafted web content may lead to an unexpected process crash

An out-of-bounds read was addressed with improved bounds checking.

Credit: Huang Xilin of Ant Group Light-Year Security Lab
CVE-2024-40785

Processing maliciously crafted web content may lead to a cross site scripting attack

This issue was addressed with improved checks.

Credit: Johan Carlsson (joaxcar)
CVE-2024-40789

Processing maliciously crafted web content may lead to an unexpected process crash

An out-of-bounds access issue was addressed with improved bounds checking.

Fix not yet public
Credit: Seunghyun Lee (@0x10n) of KAIST Hacking Lab working with Trend Micro Zero Day Initiative
CVE-2024-40794

Private Browsing tabs may be accessed without authentication

This issue was addressed through improved state management.

Bugzilla 275272 Fix not yet public
Credit: Matthew Butler
CVE-2024-44185

Processing maliciously crafted web content may lead to an unexpected process crash

The issue was addressed with improved checks.

Credit: Gary Kwong
CVE-2024-44206

A user may be able to bypass some web content restrictions

An issue in the handling of URL protocols was addressed with improved logic.

Bugzilla 280765 Fix not yet public
Credit: Andreas Jaegersberger and Ro Achterberg
Safari 17.5 May 13, 2024 · 7 WebKit CVEs
CVE-2024-27856

Processing a file may lead to unexpected app termination or arbitrary code execution

The issue was addressed with improved checks.

Credit: Maksymilian Motyl of Immunity Systems, Junsung Lee working with Trend Micro Zero Day Initiative, and ajajfxhj
CVE-2024-27834

An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication

The issue was addressed with improved checks.

Credit: Manfred Paul (@_manfp) working with Trend Micro's Zero Day Initiative
CVE-2024-27838

A maliciously crafted webpage may be able to fingerprint the user

The issue was addressed by adding additional logic.

Credit: Emilio Cobos of Mozilla
CVE-2024-27808

Processing web content may lead to arbitrary code execution

The issue was addressed with improved memory handling.

Credit: Lukas Bernhard of CISPA Helmholtz Center for Information Security
CVE-2024-27850

A maliciously crafted webpage may be able to fingerprint the user

This issue was addressed with improvements to the noise injection algorithm.

Credit: an anonymous researcher
CVE-2024-27833

Processing maliciously crafted web content may lead to arbitrary code execution

An integer overflow was addressed with improved input validation.

Credit: Manfred Paul (@_manfp) working with Trend Micro Zero Day Initiative
CVE-2024-27851

Processing maliciously crafted web content may lead to arbitrary code execution

The issue was addressed with improved bounds checks.

Credit: Nan Wang (@eternalsakura13) of 360 Vulnerability Research Institute
Safari 17.4 March 7, 2024 · 5 WebKit CVEs
CVE-2024-54658

Processing web content may lead to a denial-of-service

The issue was addressed with improved memory handling.

Bugzilla 263758 Fix not yet public
Credit: anbu1024 of SecANT
CVE-2024-23254

A malicious website may exfiltrate audio data cross-origin

The issue was addressed with improved UI handling.

Bugzilla 263795 Fix not yet public
Credit: James Lee (@Windowsrcer)
CVE-2024-23263

Processing maliciously crafted web content may prevent Content Security Policy from being enforced

A logic issue was addressed with improved validation.

Credit: Johan Carlsson (joaxcar)
CVE-2024-23280

A maliciously crafted webpage may be able to fingerprint the user

An injection issue was addressed with improved validation.

Credit: an anonymous researcher
CVE-2024-23284

Processing maliciously crafted web content may prevent Content Security Policy from being enforced

A logic issue was addressed with improved state management.

Credit: Georg Felber and Marco Squarcina