CVE-2026-43715

Overview

Advisory: Apple Security Advisory

Impact:

Description: Processing maliciously crafted web content may lead to memory corruption

Researchers: Milad Nasr and Nicholas Carlini with Claude, Anthropic

Attribute Value
CVE CVE-2026-43715
Bugzilla 313577
Component WebCore
Bug Class UAF
Severity medium
Commit 5aedb82710ba578f…
Advisory Apple Advisory

Root Cause Analysis

A use-after-free issue was addressed with improved memory management.

Files Changed

Source Files

  • Source/WebCore/css/CSSFontFace.cpp

Test Files

  • LayoutTests/fonts/font-face-load-crash-expected.txt
  • LayoutTests/fonts/font-face-load-crash.html