Week 35: 2026

Overview

Metric Value
New CVEs 241
Critical 10
High 9
Medium 222
Low 0
Commits 191
Cherry-picks 23

Bug Class Breakdown

  • LogicError: 160
  • UAF: 33
  • CrossOrigin: 12
  • OOB: 12
  • TypeConfusion: 6
  • SandboxEscape: 6
  • IntegerOverflow: 5
  • CSP Bypass: 3
  • Race: 1
  • Path Traversal: 1
  • JIT Bug: 1
  • CSRF: 1

Component Breakdown

  • WebKit: 113
  • JSC: 68
  • WebCore: 55
  • WTF: 4
  • bmalloc: 1

CVE-2024-23211

Component: WebKit
Class: LogicError
Severity: medium

A user’s private browsing activity may be visible in Settings

RCA: A privacy issue was addressed with improved handling of user preferences….


CVE-2024-23206

Bugzilla: 262699
Component: WebKit
Class: LogicError
Severity: medium
Commit: 89314de81d9bcf4a...

A maliciously crafted webpage may be able to fingerprint the user

RCA: An access issue was addressed with improved access restrictions….


CVE-2024-23213

Bugzilla: 266619
Component: WebKit
Class: LogicError
Severity: critical
Commit: 8b7b2179aa726973...

Processing web content may lead to arbitrary code execution

RCA: The issue was addressed with improved memory handling….


CVE-2024-23222

Bugzilla: 267134
Component: WebCore
Class: TypeConfusion
Severity: critical
Commit: a973b2b5b5cbd087...

Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.

RCA: A type confusion issue was addressed with improved checks….


CVE-2024-23271

Bugzilla: 265812
Component: WebCore
Class: CrossOrigin
Severity: medium
Commit: cd10fd03842d94b7...

A malicious website may cause unexpected cross-origin behavior

RCA: A logic issue was addressed with improved checks….


CVE-2024-23273

Component: WebKit
Class: LogicError
Severity: medium

Private Browsing tabs may be accessed without authentication

RCA: This issue was addressed through improved state management….


CVE-2024-54658

Bugzilla: 263758
Component: WebCore
Class: LogicError
Severity: medium
Commit: 85133f0883e415c6...

Processing web content may lead to a denial-of-service

RCA: The issue was addressed with improved memory handling….


CVE-2024-23254

Bugzilla: 263795
Component: WebCore
Class: CrossOrigin
Severity: medium
Commit: 26583bfadc4b6606...

A malicious website may exfiltrate audio data cross-origin

RCA: The issue was addressed with improved UI handling….


CVE-2024-23263

Bugzilla: 264811
Component: WebKit
Class: LogicError
Severity: medium
Commit: 15bdd42ec40b5b90...

Processing maliciously crafted web content may prevent Content Security Policy from being enforced

RCA: A logic issue was addressed with improved validation….


CVE-2024-23280

Bugzilla: 266703
Component: WebCore
Class: LogicError
Severity: medium
Commit: 17c0ad98bb1ce2d5...

A maliciously crafted webpage may be able to fingerprint the user

RCA: An injection issue was addressed with improved validation….


CVE-2024-23284

Bugzilla: 267241
Component: WebKit
Class: LogicError
Severity: medium
Commit: d4d875b3f0503741...

Processing maliciously crafted web content may prevent Content Security Policy from being enforced

RCA: A logic issue was addressed with improved state management….


CVE-2024-1580

Component: WebKit
Class: OOB
Severity: critical

Processing an image may lead to arbitrary code execution

RCA: An out-of-bounds write issue was addressed with improved input validation….


CVE-2024-27844

Component: WebKit
Class: LogicError
Severity: medium

A website’s permission dialog may persist after navigation away from the site

RCA: The issue was addressed with improved checks….


CVE-2024-27856

Bugzilla: 268765
Component: WebCore
Class: LogicError
Severity: critical
Commit: 0d0caf9579718608...

Processing a file may lead to unexpected app termination or arbitrary code execution

RCA: The issue was addressed with improved checks….


CVE-2024-27834

Bugzilla: 272750
Component: JSC
Class: LogicError
Severity: high
Commit: 3e3d0883c8495547...

An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication

RCA: The issue was addressed with improved checks….


CVE-2024-27838

Bugzilla: 262337
Component: WebKit
Class: LogicError
Severity: medium
Commit: fe6383eb455a364c...

A maliciously crafted webpage may be able to fingerprint the user

RCA: The issue was addressed by adding additional logic….


CVE-2024-27808

Bugzilla: 268221
Component: JSC
Class: LogicError
Severity: critical
Commit: b25150796310098d...

Processing web content may lead to arbitrary code execution

RCA: The issue was addressed with improved memory handling….


CVE-2024-27850

Bugzilla: 270767
Component: WebKit
Class: LogicError
Severity: medium
Commit: a451fac2e9034eaf...

A maliciously crafted webpage may be able to fingerprint the user

RCA: This issue was addressed with improvements to the noise injection algorithm….


CVE-2024-27833

Bugzilla: 271491
Component: JSC
Class: IntegerOverflow
Severity: critical
Commit: 1ea4ef8127276fd0...

Processing maliciously crafted web content may lead to arbitrary code execution

RCA: An integer overflow was addressed with improved input validation….


CVE-2024-27851

Bugzilla: 272106
Component: WebCore
Class: OOB
Severity: critical
Commit: f93441ff7ade8faf...

Processing maliciously crafted web content may lead to arbitrary code execution

RCA: The ControlStates class wrapped an OptionSet<States> with a uint16_t enum and was passed by reference through the theme rendering pipeline. Platform-specific RenderTheme implementations used t…


CVE-2024-27830

Bugzilla: 271159
Component: WTF
Class: LogicError
Severity: medium
Commit: 89ae804c9d89d646...

A maliciously crafted webpage may be able to fingerprint the user

RCA: This issue was addressed through improved state management….


CVE-2024-27820

Bugzilla: 270139
Component: JSC
Class: LogicError
Severity: critical
Commit: 6a341af34a111bdf...

Processing web content may lead to arbitrary code execution

RCA: The issue was addressed with improved memory handling….


CVE-2024-40817

Component: WebKit
Class: LogicError
Severity: medium

Visiting a website that frames malicious content may lead to UI spoofing

RCA: The issue was addressed with improved UI handling….


CVE-2024-54551

Bugzilla: 275117
Component: WebCore
Class: LogicError
Severity: medium
Commit: e73dfba967ee3b8d...

Processing web content may lead to a denial-of-service

RCA: The issue was addressed with improved memory handling….


CVE-2024-40776

Bugzilla: 273176
Component: WebKit
Class: UAF
Severity: medium
Commit: d86fef64a7c35672...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2024-40782

Bugzilla: 268770
Component: WebKit
Class: UAF
Severity: medium
Commit: fe9dc550d9a039a1...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2024-40779

Bugzilla: 275431
Component: WebKit
Class: OOB
Severity: medium
Commit: ee1d490ee70c84af...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: An out-of-bounds read was addressed with improved bounds checking….


CVE-2024-40780

Bugzilla: 275273
Component: WebKit
Class: OOB
Severity: medium
Commit: a0edcb80c674edf6...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: An out-of-bounds read was addressed with improved bounds checking….


CVE-2024-40785

Bugzilla: 273805
Component: WebKit
Class: LogicError
Severity: medium
Commit: 0a279cde8508141b...

Processing maliciously crafted web content may lead to a cross site scripting attack

RCA: This issue was addressed with improved checks….


CVE-2024-40789

Component: WebKit
Class: OOB
Severity: medium

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: An out-of-bounds access issue was addressed with improved bounds checking….


CVE-2024-4558

Bugzilla: 274165
Component: WebKit
Class: LogicError
Severity: medium
Commit: 80221c156248f327...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org….


CVE-2024-40794

Bugzilla: 275272
Component: WebKit
Class: LogicError
Severity: medium
Commit: 46d879894a746bad...

Private Browsing tabs may be accessed without authentication

RCA: This issue was addressed through improved state management….


CVE-2024-44185

Bugzilla: 276097
Component: WebKit
Class: LogicError
Severity: medium
Commit: bd43e510a6385840...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved checks….


CVE-2024-44206

Bugzilla: 280765
Component: WebKit
Class: LogicError
Severity: high
Commit: 4a6ee0b6b1b9292b...

A user may be able to bypass some web content restrictions

RCA: An issue in the handling of URL protocols was addressed with improved logic….


CVE-2024-44155

Component: WebKit
Class: SandboxEscape
Severity: medium

Maliciously crafted web content may violate iframe sandboxing policy

RCA: A custom URL scheme handling issue was addressed with improved input validation….


CVE-2024-44202

Component: WebKit
Class: LogicError
Severity: medium

Private Browsing tabs may be accessed without authentication

RCA: An authentication issue was addressed with improved state management….


CVE-2024-54467

Bugzilla: 287874
Component: WebKit
Class: CrossOrigin
Severity: medium
Commit: 70ecdca2d1973537...

A malicious website may exfiltrate data cross-origin

RCA: A cookie management issue was addressed with improved state management….


CVE-2024-44192

Bugzilla: 268770
Component: WebKit
Class: LogicError
Severity: medium
Commit: fe9dc550d9a039a1...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved checks….


CVE-2024-40866

Bugzilla: 279451
Component: WebKit
Class: LogicError
Severity: medium
Commit: 07e51b93d7e7d766...

Visiting a malicious website may lead to address bar spoofing

RCA: The issue was addressed with improved UI….


CVE-2024-44187

Bugzilla: 279452
Component: WebKit
Class: CrossOrigin
Severity: medium
Commit: 99ec4582f9e47c6c...

A malicious website may exfiltrate data cross-origin

RCA: A cross-origin issue existed with “iframe” elements. This was addressed with improved tracking of security origins….


CVE-2024-40857

Bugzilla: 268724
Component: WebKit
Class: LogicError
Severity: medium
Commit: a350c1e9191addf5...

Processing maliciously crafted web content may lead to universal cross site scripting

RCA: This issue was addressed through improved state management….


CVE-2024-44259

Component: WebKit
Class: LogicError
Severity: medium

An attacker may be able to misuse a trust relationship to download malicious content

RCA: This issue was addressed through improved state management….


CVE-2024-44229

Component: WebKit
Class: LogicError
Severity: medium

Private browsing may leak some browsing history

RCA: An information leakage was addressed with additional validation….


CVE-2024-44212

Bugzilla: 279226
Component: WebKit
Class: LogicError
Severity: medium
Commit: 11494e6772915212...

Cookies belonging to one origin may be sent to another origin

RCA: A cookie management issue was addressed with improved state management….


CVE-2024-44296

Bugzilla: 278765
Component: WebKit
Class: LogicError
Severity: medium
Commit: a946a67312c65fb9...

Processing maliciously crafted web content may prevent Content Security Policy from being enforced

RCA: The issue was addressed with improved checks….


CVE-2024-44244

Bugzilla: 279780
Component: WebKit
Class: LogicError
Severity: medium
Commit: 33330e8a218db45a...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A memory corruption issue was addressed with improved input validation….


CVE-2024-44308

Bugzilla: 283063
Component: WebKit
Class: LogicError
Severity: critical
Commit: 82abacffb221fb67...

Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

RCA: The issue was addressed with improved checks….


CVE-2024-44309

Bugzilla: 283095
Component: WebKit
Class: LogicError
Severity: medium
Commit: 3845740eb3e24283...

Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

RCA: A cookie management issue was addressed with improved state management….


CVE-2024-44246

Component: WebKit
Class: LogicError
Severity: medium

On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the originating IP address to the website

RCA: The issue was addressed with improved routing of Safari-originated requests….


CVE-2024-54542

Component: WebKit
Class: LogicError
Severity: medium

Private Browsing tabs may be accessed without authentication

RCA: An authentication issue was addressed with improved state management….


CVE-2024-54479

Bugzilla: 278497
Component: WebKit
Class: LogicError
Severity: medium
Commit: 60532cbe64e57216...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved checks….


CVE-2024-54502

Bugzilla: 281912
Component: WebKit
Class: LogicError
Severity: medium
Commit: a5aab1fd879a56b6...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved checks….


CVE-2024-54508

Bugzilla: 282180
Component: WebKit
Class: LogicError
Severity: medium
Commit: a786924faa7f8ca0...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2024-54505

Bugzilla: 282661
Component: JSC
Class: TypeConfusion
Severity: medium
Commit: 2d5e29d47324834c...

Processing maliciously crafted web content may lead to memory corruption

RCA: A type confusion issue was addressed with improved memory handling….


CVE-2024-54534

Bugzilla: 277967
Component: WebKit
Class: LogicError
Severity: medium
Commit: ccef7b85cc9b91a1...

Processing maliciously crafted web content may lead to memory corruption

RCA: The issue was addressed with improved memory handling….


CVE-2024-54543

Bugzilla: 282450
Component: WebKit
Class: LogicError
Severity: medium
Commit: c4bc08c26ba9c8b7...

Processing maliciously crafted web content may lead to memory corruption

RCA: The issue was addressed with improved memory handling….


CVE-2025-24169

Component: WebKit
Class: LogicError
Severity: high

A malicious app may be able to bypass browser extension authentication

RCA: A logging issue was addressed with improved data redaction….


CVE-2025-24113

Component: WebKit
Class: LogicError
Severity: medium

Visiting a malicious website may lead to user interface spoofing

RCA: The issue was addressed with improved UI….


CVE-2025-24128

Component: WebKit
Class: LogicError
Severity: medium

Visiting a malicious website may lead to address bar spoofing

RCA: The issue was addressed by adding additional logic….


CVE-2025-24189

Bugzilla: 284332
Component: WebKit
Class: LogicError
Severity: medium
Commit: 9cee5daeabd138d0...

Processing maliciously crafted web content may lead to memory corruption

RCA: The issue was addressed with improved checks….


CVE-2025-24143

Bugzilla: 283117
Component: WebKit
Class: LogicError
Severity: medium
Commit: 5867423d3c559666...

A maliciously crafted webpage may be able to fingerprint the user

RCA: The issue was addressed with improved access restrictions to the file system….


CVE-2025-24158

Bugzilla: 283889
Component: WebKit
Class: LogicError
Severity: medium
Commit: bfe3f27cc9be546f...

Processing web content may lead to a denial-of-service

RCA: The issue was addressed with improved memory handling….


CVE-2025-24162

Bugzilla: 284159
Component: WebKit
Class: LogicError
Severity: medium
Commit: c7d10c6fc5fa4308...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: This issue was addressed through improved state management….


CVE-2025-24150

Bugzilla: 283718
Component: WebKit
Class: LogicError
Severity: medium
Commit: fed47c6e0559b588...

Copying a URL from Web Inspector may lead to command injection

RCA: A privacy issue was addressed with improved handling of files….


CVE-2025-24201

Bugzilla: 285858
Component: WebKit
Class: OOB
Severity: medium
Commit: 7d784721e440d049...

Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.)

RCA: An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions….


CVE-2025-24180

Component: WebKit
Class: LogicError
Severity: medium

A malicious website may be able to claim WebAuthn credentials from another website that shares a registrable suffix

RCA: The issue was addressed with improved input validation….


CVE-2025-30466

Component: WebKit
Class: CrossOrigin
Severity: high

A website may be able to bypass Same Origin Policy

RCA: This issue was addressed through improved state management….


CVE-2025-30467

Component: WebKit
Class: LogicError
Severity: medium

Visiting a malicious website may lead to address bar spoofing

RCA: The issue was addressed with improved checks….


CVE-2025-31192

Component: WebKit
Class: LogicError
Severity: medium

A website may be able to access sensor information without user consent

RCA: The issue was addressed with improved checks….


CVE-2025-24192

Component: WebKit
Class: LogicError
Severity: medium

Visiting a website may leak sensitive data

RCA: A script imports issue was addressed with improved isolation….


CVE-2025-24264

Bugzilla: 285892
Component: WebKit
Class: LogicError
Severity: medium
Commit: 71951f425f93be30...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: The issue was addressed with improved memory handling….


CVE-2025-24216

Bugzilla: 284055
Component: WebCore
Class: LogicError
Severity: medium
Commit: b879a659b19009b9...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: The issue was addressed with improved memory handling….


CVE-2025-24209

Bugzilla: 286462
Component: WebCore
Class: IntegerOverflow
Severity: medium
Commit: 575e5800d5bb2215...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A buffer overflow issue was addressed with improved memory handling….


CVE-2025-24208

Bugzilla: 286381
Component: WebKit
Class: LogicError
Severity: medium
Commit: 609e8c7a932f28b7...

Loading a malicious iframe may lead to a cross-site scripting attack

RCA: A permissions issue was addressed with additional restrictions….


CVE-2025-30427

Bugzilla: 285643
Component: JSC
Class: UAF
Severity: medium
Commit: d7bd7d8f7cdf153d...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2025-30425

Bugzilla: 286580
Component: WebCore
Class: LogicError
Severity: medium
Commit: df02f84bef7163f3...

A malicious website may be able to track users in Safari private browsing mode

RCA: This issue was addressed through improved state management….


CVE-2025-31266

Component: WebKit
Class: LogicError
Severity: medium

A website may be able to spoof the domain name in the title of a pop-up window

RCA: A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name…


CVE-2025-24213

Bugzilla: 286694
Component: WebCore
Class: TypeConfusion
Severity: medium
Commit: c1b04541303ec183...

A type confusion issue could lead to memory corruption

RCA: This issue was addressed with improved handling of floats….


CVE-2025-31223

Bugzilla: 289387
Component: JSC
Class: LogicError
Severity: medium
Commit: 92e69a181eb39835...

Processing maliciously crafted web content may lead to memory corruption

RCA: The issue was addressed with improved checks….


CVE-2025-31238

Bugzilla: 289653
Component: WebCore
Class: LogicError
Severity: medium
Commit: a23df0dfbec0c9df...

Processing maliciously crafted web content may lead to memory corruption

RCA: The issue was addressed with improved checks….


CVE-2025-24223

Bugzilla: 287577
Component: WebKit
Class: LogicError
Severity: medium

Processing maliciously crafted web content may lead to memory corruption

RCA: The issue was addressed with improved memory handling….


CVE-2025-31204

Bugzilla: 291506
Component: JSC
Class: LogicError
Severity: medium
Commit: 265dbd5abf60768a...

Processing maliciously crafted web content may lead to memory corruption

RCA: The issue was addressed with improved memory handling….


CVE-2025-31217

Bugzilla: 289677
Component: WebKit
Class: LogicError
Severity: medium
Commit: 2f1c7a102f89c395...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: The issue was addressed with improved input validation….


CVE-2025-31215

Bugzilla: 288814
Component: JSC
Class: LogicError
Severity: medium
Commit: ac09d743b1828ad9...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved checks….


CVE-2025-31206

Bugzilla: 290834
Component: JSC
Class: TypeConfusion
Severity: medium
Commit: 2a545562709ac7a6...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A type confusion issue was addressed with improved state handling….


CVE-2025-31205

Bugzilla: 290992
Component: WebCore
Class: CrossOrigin
Severity: medium
Commit: 647e80ac22b36756...

A malicious website may exfiltrate data cross-origin

RCA: The issue was addressed with improved checks….


CVE-2025-31257

Bugzilla: 290985
Component: WebCore
Class: LogicError
Severity: medium
Commit: ddbf9329b2ca0320...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: This issue was addressed with improved memory handling….


CVE-2025-24188

Component: WebKit
Class: LogicError
Severity: medium

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A logic issue was addressed with improved checks….


CVE-2025-43229

Bugzilla: 285927
Component: WebKit
Class: LogicError
Severity: medium
Commit: feb7725d8aedfa96...

Processing maliciously crafted web content may lead to universal cross site scripting

RCA: This issue was addressed through improved state management….


CVE-2025-43228

Bugzilla: 294374
Component: WebKit
Class: LogicError
Severity: medium
Commit: 632a293bf7754147...

Visiting a malicious website may lead to address bar spoofing

RCA: The issue was addressed with improved UI….


CVE-2025-43227

Bugzilla: 292888
Component: WTF
Class: LogicError
Severity: medium
Commit: c3811ccef9594d3a...

Processing maliciously crafted web content may disclose sensitive user information

RCA: This issue was addressed through improved state management….


CVE-2025-31278

Bugzilla: 291742
Component: JSC
Class: LogicError
Severity: medium
Commit: 90aa8070e1b674f9...

Processing maliciously crafted web content may lead to memory corruption

RCA: The issue was addressed with improved memory handling….


CVE-2025-31277

Bugzilla: 291745
Component: JSC
Class: LogicError
Severity: medium
Commit: 716536ce98d6f8d4...

Processing maliciously crafted web content may lead to memory corruption

RCA: The issue was addressed with improved memory handling….


CVE-2025-31273

Bugzilla: 293579
Component: JSC
Class: LogicError
Severity: medium
Commit: a05032c6961001c2...

Processing maliciously crafted web content may lead to memory corruption

RCA: The issue was addressed with improved memory handling….


CVE-2025-43240

Bugzilla: 293994
Component: WebKit
Class: LogicError
Severity: medium
Commit: 0578185b8a7484c5...

A download’s origin may be incorrectly associated

RCA: A logic issue was addressed with improved checks….


CVE-2025-43214

Bugzilla: 292599
Component: JSC
Class: LogicError
Severity: medium
Commit: 666190cff29d03c1...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: The issue was addressed with improved memory handling….


CVE-2025-43213

Bugzilla: 292621
Component: JSC
Class: LogicError
Severity: medium
Commit: 946696720edc253e...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: The issue was addressed with improved memory handling….


CVE-2025-43212

Bugzilla: 293197
Component: JSC
Class: LogicError
Severity: medium
Commit: 240b9cb9889168bc...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: The issue was addressed with improved memory handling….


CVE-2025-43211

Bugzilla: 293730
Component: JSC
Class: LogicError
Severity: medium
Commit: 58218eebdaf5770a...

Processing web content may lead to a denial-of-service

RCA: The issue was addressed with improved memory handling….


CVE-2025-43265

Bugzilla: 294182
Component: JSC
Class: OOB
Severity: medium
Commit: d96ab2fa64c62763...

Processing maliciously crafted web content may disclose internal states of the app

RCA: An out-of-bounds read was addressed with improved input validation….


CVE-2025-43216

Bugzilla: 295382
Component: WebCore
Class: UAF
Severity: medium
Commit: 4637324afb310494...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2025-43327

Component: WebKit
Class: LogicError
Severity: medium

Visiting a malicious website may lead to address bar spoofing

RCA: The issue was addressed by adding additional logic….


CVE-2025-31254

Component: WebKit
Class: LogicError
Severity: medium

Processing maliciously crafted web content may lead to unexpected URL redirection

RCA: This issue was addressed with improved URL validation….


CVE-2025-43356

Bugzilla: 296153
Component: WebKit
Class: LogicError
Severity: medium
Commit: c420ed2f891b1948...

A website may be able to access sensor information without user consent

RCA: The issue was addressed with improved handling of caches….


CVE-2025-43272

Bugzilla: 294550
Component: WebCore
Class: LogicError
Severity: medium
Commit: fa85413077accf8c...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: The issue was addressed with improved memory handling….


CVE-2025-43343

Bugzilla: 296490
Component: JSC
Class: LogicError
Severity: medium
Commit: 899a38cf9a50a555...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2025-43342

Bugzilla: 296042
Component: JSC
Class: LogicError
Severity: medium
Commit: 8b9fc1b8515151cc...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A correctness issue was addressed with improved checks….


CVE-2025-43419

Bugzilla: 293895
Component: WebKit
Class: LogicError
Severity: medium
Commit: bcb47de34ff759fc...

Processing maliciously crafted web content may lead to memory corruption

RCA: The issue was addressed with improved memory handling….


CVE-2025-43376

Bugzilla: 295943
Component: WebCore
Class: LogicError
Severity: medium
Commit: 5247bc4ad4b98d16...

A remote attacker may be able to view leaked DNS queries with Private Relay turned on

RCA: A logic issue was addressed with improved state management….


CVE-2025-43368

Bugzilla: 296276
Component: WebKit
Class: UAF
Severity: medium
Commit: 674611789255a98f...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2025-43493

Component: WebKit
Class: LogicError
Severity: medium

Visiting a malicious website may lead to address bar spoofing

RCA: The issue was addressed with improved checks….


CVE-2025-43503

Component: WebKit
Class: LogicError
Severity: medium

Visiting a malicious website may lead to user interface spoofing

RCA: An inconsistent user interface issue was addressed with improved state management….


CVE-2025-43502

Component: WebKit
Class: LogicError
Severity: high

An app may be able to bypass certain Privacy preferences

RCA: A privacy issue was addressed by removing sensitive data….


CVE-2025-43480

Bugzilla: 276208
Component: WebCore
Class: CrossOrigin
Severity: medium
Commit: 0473037b55025aeb...

A malicious website may exfiltrate data cross-origin

RCA: The issue was addressed with improved checks….


CVE-2025-43458

Bugzilla: 296693
Component: WebKit
Class: LogicError
Severity: medium

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: This issue was addressed through improved state management….


CVE-2025-43430

Bugzilla: 298196
Component: JSC
Class: LogicError
Severity: medium
Commit: b107f7698299c89d...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: This issue was addressed through improved state management….


CVE-2025-43427

Bugzilla: 298628
Component: JSC
Class: LogicError
Severity: medium
Commit: 127c1d5c4d40d679...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: This issue was addressed through improved state management….


CVE-2025-43443

Bugzilla: 299843
Component: WebKit
Class: LogicError
Severity: medium

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: This issue was addressed with improved checks….


CVE-2025-43441

Bugzilla: 298496
Component: JSC
Class: LogicError
Severity: medium
Commit: 11eaa3910d44873a...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2025-43435

Bugzilla: 299391
Component: WebCore
Class: LogicError
Severity: medium
Commit: cd945f0c3fe21294...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2025-43425

Bugzilla: 298851
Component: JSC
Class: LogicError
Severity: medium
Commit: fcd2a8fc20dda5aa...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2025-43440

Bugzilla: 298126
Component: JSC
Class: LogicError
Severity: medium
Commit: 78b31d59089f6578...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: This issue was addressed with improved checks…


CVE-2025-43438

Bugzilla: 297662
Component: JSC
Class: UAF
Severity: medium
Commit: 045fd8ec92379f84...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2025-43457

Bugzilla: 298606
Component: JSC
Class: UAF
Severity: medium
Commit: f014a32890763b13...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2025-43434

Bugzilla: 297958
Component: JSC
Class: UAF
Severity: medium
Commit: ef9304e0e82bf304...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2025-43433

Bugzilla: 298093
Component: WebKit
Class: LogicError
Severity: medium

Processing maliciously crafted web content may lead to memory corruption

RCA: The issue was addressed with improved memory handling….


CVE-2025-43431

Bugzilla: 298194
Component: JSC
Class: LogicError
Severity: medium
Commit: d4b9e6993567d3c3...

Processing maliciously crafted web content may lead to memory corruption

RCA: The issue was addressed with improved memory handling….


CVE-2025-43432

Bugzilla: 299313
Component: JSC
Class: UAF
Severity: medium
Commit: d329e095fc8c1874...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2025-43429

Bugzilla: 298232
Component: JSC
Class: IntegerOverflow
Severity: medium
Commit: 7a45348e0e20683e...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A buffer overflow was addressed with improved bounds checking….


CVE-2025-43421

Bugzilla: 300718
Component: JSC
Class: LogicError
Severity: medium
Commit: 56f026944a16a4ba...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: Multiple issues were addressed by disabling array allocation sinking….


CVE-2025-43392

Bugzilla: 297566
Component: WebCore
Class: CrossOrigin
Severity: medium
Commit: 569f9f07502847a5...

A website may exfiltrate image data cross-origin

RCA: The issue was addressed with improved handling of caches….


CVE-2024-8906

Component: WebKit
Class: LogicError
Severity: medium

A download’s origin may be incorrectly associated

RCA: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org ….


CVE-2025-46282

Bugzilla: 295941
Component: WebKit
Class: LogicError
Severity: high
Commit: 50b0e0bcc62b2450...

An app may be able to access sensitive user data

RCA: The issue was addressed with additional permissions checks….


CVE-2025-43541

Bugzilla: 301257
Component: JSC
Class: TypeConfusion
Severity: medium
Commit: ef1aba9e847aa7b6...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A type confusion issue was addressed with improved state handling….


CVE-2025-43536

Bugzilla: 301726
Component: JSC
Class: UAF
Severity: medium
Commit: 1025bd18c9c7bd3d...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2025-43535

Bugzilla: 300774
Component: JSC
Class: LogicError
Severity: medium
Commit: 26d50a4d4b2df76c...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2025-46298

Bugzilla: 301468
Component: JSC
Class: LogicError
Severity: medium
Commit: a1a6185cc83ec556...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2025-43501

Bugzilla: 301371
Component: WTF
Class: IntegerOverflow
Severity: medium
Commit: ad4544045d66266c...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A buffer overflow issue was addressed with improved memory handling….


CVE-2025-43531

Bugzilla: 301940
Component: bmalloc
Class: Race
Severity: medium
Commit: 39a5ac27139893e6...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A race condition was addressed with improved state handling….


CVE-2025-43529

Bugzilla: 302502
Component: JSC
Class: UAF
Severity: critical
Commit: b21a503b579a8ab1...

Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2025-14174

Bugzilla: 303614
Component: WebKit
Class: LogicError
Severity: medium

Processing maliciously crafted web content may lead to memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-43529 was also issued in response to this report.

RCA: A memory corruption issue was addressed with improved validation….


CVE-2025-46299

Bugzilla: 299518
Component: WebKit
Class: LogicError
Severity: medium

Processing maliciously crafted web content may disclose internal states of the app

RCA: A memory initialization issue was addressed with improved memory handling….


CVE-2025-43511

Bugzilla: 300926
Component: WebCore
Class: UAF
Severity: medium
Commit: bb6619c2421179b0...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-20652

Bugzilla: 303959
Component: WebCore
Class: LogicError
Severity: medium
Commit: 7afdc436a98c9771...

A remote attacker may be able to cause a denial-of-service

RCA: The issue was addressed with improved memory handling….


CVE-2026-20608

Bugzilla: 303357
Component: JSC
Class: LogicError
Severity: medium
Commit: 672cdd38781cce18...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: This issue was addressed through improved state management….


CVE-2026-20676

Bugzilla: 305020
Component: WebCore
Class: LogicError
Severity: medium
Commit: 0f4832ce0eea25af...

A website may be able to track users through Safari web extensions

RCA: This issue was addressed through improved state management….


CVE-2026-20644

Bugzilla: 303444
Component: JSC
Class: LogicError
Severity: medium
Commit: 4572dd488e4eb6e0...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-20636

Bugzilla: 304657
Component: WebKit
Class: LogicError
Severity: medium

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-20635

Bugzilla: 304661
Component: WebKit
Class: LogicError
Severity: medium

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-20665

Bugzilla: 304951
Component: WebCore
Class: LogicError
Severity: medium
Commit: b4390e8352b7dc2e...

Processing maliciously crafted web content may prevent Content Security Policy from being enforced

RCA: This issue was addressed through improved state management….


CVE-2026-20643

Bugzilla: 306050
Component: WebCore
Class: CrossOrigin
Severity: high
Commit: b537a57c092d669f...

Processing maliciously crafted web content may bypass Same Origin Policy

RCA: A cross-origin issue in the Navigation API was addressed with improved input validation….


CVE-2026-28871

Bugzilla: 305859
Component: WebCore
Class: LogicError
Severity: medium
Commit: 59efb640749a3024...

Visiting a maliciously crafted website may lead to a cross-site scripting attack

RCA: A logic issue was addressed with improved checks….


CVE-2026-20664

Bugzilla: 306136
Component: JSC
Class: LogicError
Severity: medium
Commit: 6b357f32c6075bb8...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-28857

Bugzilla: 307723
Component: JSC
Class: LogicError
Severity: medium
Commit: 4c82252b8b2face3...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-28861

Bugzilla: 307014
Component: WebCore
Class: LogicError
Severity: medium
Commit: 795ef8a1ac92461c...

A malicious website may be able to access script message handlers intended for other origins

RCA: A logic issue was addressed with improved state management….


CVE-2026-28859

Bugzilla: 308248
Component: WebKit
Class: SandboxEscape
Severity: medium
Commit: 6aacf62000967a62...

A malicious website may be able to process restricted web content outside the sandbox

RCA: The issue was addressed with improved memory handling….


CVE-2026-20691

Bugzilla: 306827
Component: WebKit
Class: LogicError
Severity: medium
Commit: dfe2e0efc8182466...

A maliciously crafted webpage may be able to fingerprint the user

RCA: An authorization issue was addressed with improved state management….


CVE-2026-43660

Bugzilla: 308906
Component: WebCore
Class: CSP Bypass
Severity: medium
Commit: f8ed382fb244cc24...

Processing maliciously crafted web content may prevent Content Security Policy from being enforced

RCA: CSP blob URL iframe was only inheriting the last CSP header when a document had multiple enforced CSP headers. ContentSecurityPolicyResponseHeaders::addPolicyHeadersTo used setHTTPHeaderField which ov…


CVE-2026-28907

Bugzilla: 308675
Component: WebKit
Class: CSP Bypass
Severity: medium
Commit: 5d910749e9023a7d...

Processing maliciously crafted web content may prevent Content Security Policy from being enforced

RCA: CSP path matching did not percent-decode path segments before comparison, allowing %2F..%2F path traversal to bypass script-src path restrictions. Fix: pathMatches() now splits on /, then percent-deco…


CVE-2026-28962

Bugzilla: 309698
Component: WebCore
Class: Path Traversal
Severity: medium
Commit: 08d7278db550a539...

Processing maliciously crafted web content may disclose sensitive user information

RCA: Pasteboard drag-and-drop and file upload paths were not validated against an allowlist. A compromised web process could register attachment identifiers pointing to arbitrary files (e.g. /etc/passwd). …


CVE-2026-43658

Bugzilla: 307669
Component: JSC
Class: UAF
Severity: medium
Commit: 9a16de46f205d3c7...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: WebAssembly BBQCallee could be freed while its OMGOSREntryCallee was still being referenced during callsite repatching, causing use-after-free. Fix: updateCallsitesToCallUs now keeps BBQCallee alive v…


CVE-2026-28984

Bugzilla: 311883
Component: JSC
Class: LogicError
Severity: medium
Commit: eba64ef44de39509...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-28905

Bugzilla: 308545
Component: WebKit
Class: JIT Bug
Severity: medium
Commit: 392f508eef947d28...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: FTL JIT OSR exit had a phantom array unwritten slot bug where an array’s length was not properly updated after arr.map(f) when f returned the same array. This is a JIT compilation bug in FTL’s OSR exi…


CVE-2026-28847

Bugzilla: 308707
Component: JSC
Class: LogicError
Severity: medium
Commit: e5368156542a8414...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-28904

Bugzilla: 309601
Component: JSC
Class: LogicError
Severity: medium
Commit: 7663d811d06c3255...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-28955

Bugzilla: 310880
Component: WebCore
Class: LogicError
Severity: medium
Commit: 5233199dcb0cd58c...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-28903

Bugzilla: 310303
Component: JSC
Class: LogicError
Severity: medium
Commit: fa0214fe9a50ec15...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-28953

Bugzilla: 309628
Component: WebKit
Class: LogicError
Severity: medium
Commit: 9161e71798e985c6...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-28902

Bugzilla: 309861
Component: JSC
Class: LogicError
Severity: medium
Commit: c8525868de350de8...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-28901

Bugzilla: 310207
Component: JSC
Class: LogicError
Severity: medium
Commit: c5d68122b2faf486...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-28913

Bugzilla: 311631
Component: WebKit
Class: LogicError
Severity: medium
Commit: a9f9b9ecfd4bcdaf...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-28883

Bugzilla: 313939
Component: WebKit
Class: UAF
Severity: medium

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-28958

Bugzilla: 311228
Component: WebCore
Class: CSRF
Severity: high
Commit: d995144a1f1cdc33...

An app may be able to access sensitive user data

RCA: FrameLoader::load called addSameSiteInfoToRequestIfNeeded before checking if the initiator should inherit the security origin from its owner. This caused SameSite=Strict cookies to be sent on cross-si…


CVE-2026-28917

Bugzilla: 310527
Component: WebKit
Class: LogicError
Severity: medium
Commit: cf2e67ecb9131bdf...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved input validation….


CVE-2026-28947

Bugzilla: 310234
Component: JSC
Class: UAF
Severity: medium
Commit: 76b34686210f4f67...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: JSWebAssemblyInstance destructor called m_anchor->tearDown() after unregistering ICs and destroying baseline data. If GC ran during destruction, the anchor could be accessed after partial teardown. Fi…


CVE-2026-28946

Bugzilla: 310544
Component: WebCore
Class: UAF
Severity: medium
Commit: 869d5c55313783da...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-28942

Bugzilla: 312180
Component: WebCore
Class: UAF
Severity: medium
Commit: 70753442a3d86ab5...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-28971

Bugzilla: 311288
Component: WebKit
Class: LogicError
Severity: medium
Commit: 4b574bf8287b6b57...

A malicious iframe may use another website’s download settings

RCA: Safe Browsing checks were asynchronous and could complete after the navigation policy decision had already proceeded to download. This allowed malicious downloads to start before the Safe Browsing war…


CVE-2026-43670

Bugzilla: 309004
Component: WebKit
Class: CSP Bypass
Severity: high
Commit: cb23cbdfde76d52c...

Processing maliciously crafted web content may bypass Content Security Policy

RCA: AudioWorklet and PaintWorklet did not inherit the owner document’s CSP, allowing eval() and remote script loading even when CSP blocked them. Fix: WorkletParameters now carries contentSecurityPolicyRe…


CVE-2026-28944

Bugzilla: 311131
Component: WebCore
Class: LogicError
Severity: medium
Commit: 8384c8455e7b5bc4...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: WebRTC encoded stream transformer allowed writing audio frames to video streams and vice versa. RTCEncodedStreamProducer::writeFrame did not validate that the incoming frame type matched the stream ty…


CVE-2026-43704

Bugzilla: 314642
Component: WebKit
Class: UAF
Severity: medium
Commit: 1759ab219c63940b...

A malicious web extension may be able to cause an unexpected process crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-43700

Bugzilla: 315368
Component: WebCore
Class: CrossOrigin
Severity: medium
Commit: 67b563b85f480c70...

Processing maliciously crafted web content may disclose sensitive user information

RCA: A cross-origin issue was addressed with improved tracking of security origins….


CVE-2026-43735

Bugzilla: 313357
Component: WebCore
Class: CrossOrigin
Severity: medium
Commit: 8254b44eba7e8bfb...

A malicious website may exfiltrate data cross-origin

RCA: The issue was addressed with improved checks….


CVE-2026-43734

Bugzilla: 313693
Component: WebCore
Class: UAF
Severity: medium
Commit: 5b76ce8531919008...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-43726

Bugzilla: 313857
Component: JSC
Class: UAF
Severity: medium
Commit: a7e4fdb9545042ae...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-43709

Bugzilla: 314398
Component: WebKit
Class: UAF
Severity: medium
Commit: 9d2cc8c9895d51eb...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-43699

Bugzilla: 317227
Component: WebKit
Class: UAF
Severity: medium

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-43742

Bugzilla: 315161
Component: WebCore
Class: UAF
Severity: medium
Commit: 034f2fbd9b69edba...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-43732

Bugzilla: 313085
Component: WebKit
Class: LogicError
Severity: medium
Commit: 5be1236842b36137...

Processing maliciously crafted web content may disclose sensitive user information

RCA: A path handling issue was addressed with improved validation….


CVE-2026-43731

Bugzilla: 314115
Component: WebKit
Class: UAF
Severity: medium
Commit: 866892a3052f6739...

Processing maliciously crafted web content may lead to memory corruption

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-43715

Bugzilla: 313577
Component: WebCore
Class: UAF
Severity: medium
Commit: 5aedb82710ba578f...

Processing maliciously crafted web content may lead to memory corruption

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-43727

Bugzilla: 313691
Component: WebCore
Class: UAF
Severity: medium
Commit: c5036aadbde48318...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-43725

Bugzilla: 312832
Component: WebKit
Class: SandboxEscape
Severity: medium
Commit: ccf0c4874cb25ab1...

A malicious website may be able to process restricted web content outside the sandbox

RCA: The issue was addressed with improved input validation….


CVE-2026-43663

Bugzilla: 312781
Component: JSC
Class: LogicError
Severity: medium
Commit: 13bfbf94f49eab45...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-39872

Bugzilla: 313528
Component: WebCore
Class: LogicError
Severity: medium
Commit: 8912cf5b00c44e5c...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-43712

Bugzilla: 314235
Component: JSC
Class: LogicError
Severity: medium
Commit: e96472d9cab94158...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-43716

Bugzilla: 313473
Component: JSC
Class: LogicError
Severity: medium
Commit: a012babd4f1611a4...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-43676

Bugzilla: 317231
Component: WebKit
Class: OOB
Severity: medium

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: An out-of-bounds access issue was addressed with improved bounds checking….


CVE-2026-43740

Bugzilla: 308046
Component: JSC
Class: LogicError
Severity: medium
Commit: 2693828e8d7300d8...

Processing maliciously crafted web content may result in the disclosure of process memory

RCA: The issue was addressed with improved memory handling….


CVE-2026-43713

Bugzilla: 314806
Component: WebCore
Class: LogicError
Severity: medium
Commit: 73645abad282e490...

Visiting a website may leak sensitive data

RCA: A permissions issue was addressed with additional restrictions….


CVE-2026-43708

Bugzilla: 315306
Component: WebKit
Class: CrossOrigin
Severity: medium
Commit: 971435fdd3868e7f...

A malicious website may exfiltrate data cross-origin

RCA: The issue was addressed with improved input validation….


CVE-2026-43707

Bugzilla: 315951
Component: WebKit
Class: LogicError
Severity: medium

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A memory corruption issue was addressed with improved memory handling….


CVE-2026-43705

Bugzilla: 314528
Component: WebCore
Class: TypeConfusion
Severity: medium
Commit: 8fd92b1021d310b2...

Processing maliciously crafted web content may lead to memory corruption

RCA: A type confusion issue was addressed with improved checks….


CVE-2026-43701

Bugzilla: 315004
Component: WebCore
Class: SandboxEscape
Severity: medium
Commit: f23ffb5a845006c8...

A malicious website may be able to process restricted web content outside the sandbox

RCA: The issue was addressed with improved checks….


CVE-2026-43745

Bugzilla: 315365
Component: JSC
Class: OOB
Severity: medium
Commit: 0f0de8f2a0582988...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: An out-of-bounds write issue was addressed with improved input validation….


CVE-2026-43720

Bugzilla: 313175
Component: WebCore
Class: UAF
Severity: medium
Commit: 040ef6e21ffac03b...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-43721

Bugzilla: 313478
Component: WebCore
Class: LogicError
Severity: medium
Commit: d8576e6cceeb0595...

A malicious website may be able to silently hijack clipboard data

RCA: This issue was addressed through improved state management….


CVE-2026-28979

Bugzilla: 317324
Component: WebKit
Class: OOB
Severity: medium

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: An out-of-bounds access issue was addressed with improved bounds checking….


CVE-2026-43718

Bugzilla: 313350
Component: WebKit
Class: IntegerOverflow
Severity: medium

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A stack overflow was addressed with improved input validation….


CVE-2026-43717

Bugzilla: 313351
Component: WebKit
Class: UAF
Severity: medium

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-43746

Bugzilla: 314090
Component: WebKit
Class: UAF
Severity: medium

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-64713

Bugzilla: 316827
Component: WebCore
Class: LogicError
Severity: medium
Commit: 52cacff4c9e7d9eb...

Websites may know if the user has visited a given link

RCA: This issue was addressed with improved checks….


CVE-2026-64730

Bugzilla: 311660
Component: WTF
Class: LogicError
Severity: medium
Commit: 1ab2bb4ff37e91e0...

Visiting a website that frames malicious content may lead to UI spoofing

RCA: The issue was addressed with improved UI….


CVE-2026-64728

Bugzilla: 313220
Component: WebCore
Class: SandboxEscape
Severity: medium
Commit: c52bbb5187e1602b...

Maliciously crafted web content may violate iframe sandboxing policy

RCA: A permissions issue was addressed with improved validation….


CVE-2026-64783

Bugzilla: 313521
Component: WebCore
Class: UAF
Severity: medium
Commit: be08720593705c04...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-64757

Bugzilla: 315082
Component: JSC
Class: LogicError
Severity: medium
Commit: 72272dcc4feb8412...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A memory corruption issue was addressed with improved state management….


CVE-2026-43804

Bugzilla: 316816
Component: WebCore
Class: LogicError
Severity: medium
Commit: 2057f457fb75d4e5...

Visiting a website may lead to an app denial-of-service

RCA: This issue was addressed through improved state management….


CVE-2026-43821

Bugzilla: 314867
Component: WebKit
Class: SandboxEscape
Severity: medium
Commit: 74d0c628ff2d82e9...

An app may be able to read files outside of its sandbox

RCA: An access issue was addressed with improved access restrictions….


CVE-2026-64718

Bugzilla: 313935
Component: WebCore
Class: UAF
Severity: medium
Commit: 95f9f59bb141325d...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-64719

Bugzilla: 319404
Component: WebKit
Class: OOB
Severity: medium

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: An out-of-bounds access issue was addressed with improved bounds checking….


CVE-2026-64784

Bugzilla: 317632
Component: JSC
Class: OOB
Severity: medium
Commit: 97df94ead028cddc...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: UnlinkedMetadataTable::finalize() computed metadata buffer offsets using unchecked unsigned arithmetic. When compiling JavaScript functions with tens of millions of bytecode instructions, the cumulati…


CVE-2026-43795

Bugzilla: 313452
Component: WebCore
Class: LogicError
Severity: medium
Commit: ce11a67281dafaa7...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-65338

Bugzilla: 318348
Component: JSC
Class: LogicError
Severity: medium
Commit: 26aa84fcd527016d...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: The issue was addressed with improved memory handling….


CVE-2026-65341

Bugzilla: 318405
Component: WebCore
Class: LogicError
Severity: medium
Commit: 34249048d66d342f...

Processing maliciously crafted web content may lead to memory corruption

RCA: The issue was addressed with improved memory handling….


CVE-2026-64782

Bugzilla: 321480
Component: WebKit
Class: LogicError
Severity: medium

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A memory corruption vulnerability was addressed with improved locking….


CVE-2026-64781

Bugzilla: 321484
Component: WebKit
Class: LogicError
Severity: medium

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: The issue was addressed with improved input validation….


CVE-2026-65351

Bugzilla: 321517
Component: WebKit
Class: LogicError
Severity: medium

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: This issue was addressed through improved state management….


CVE-2026-65340

Bugzilla: 316996
Component: JSC
Class: LogicError
Severity: medium
Commit: 30b9a27b47e842c4...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: This issue was addressed through improved state management….


CVE-2026-65337

Bugzilla: 317142
Component: JSC
Class: LogicError
Severity: medium
Commit: 7920db18a51b134b...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: This issue was addressed through improved state management….


CVE-2026-65336

Bugzilla: 317349
Component: JSC
Class: LogicError
Severity: medium
Commit: 5b76326e8fc95ec2...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: This issue was addressed through improved state management….


CVE-2026-65335

Bugzilla: 316723
Component: JSC
Class: LogicError
Severity: medium
Commit: d74d692503fce0f3...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: This issue was addressed through improved state management….


CVE-2026-65333

Bugzilla: 317603
Component: JSC
Class: LogicError
Severity: medium
Commit: 7d867192b7ab40a0...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: This issue was addressed through improved state management….


CVE-2026-65332

Bugzilla: 317450
Component: JSC
Class: LogicError
Severity: medium
Commit: 8f229fb72961093d...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: This issue was addressed through improved state management….


CVE-2026-65331

Bugzilla: 317611
Component: JSC
Class: LogicError
Severity: medium
Commit: 03a07e4200891271...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: This issue was addressed through improved state management….


CVE-2026-64715

Bugzilla: 316347
Component: JSC
Class: UAF
Severity: medium
Commit: 1d5c10e2f9c8f313...

Processing maliciously crafted web content may lead to an unexpected process crash

RCA: A use-after-free issue was addressed with improved memory management….


CVE-2026-64780

Bugzilla: 316918
Component: JSC
Class: LogicError
Severity: medium
Commit: 9a17cd1100ad6cd4...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: The issue was addressed with improved checks….


CVE-2026-65334

Bugzilla: 316791
Component: JSC
Class: LogicError
Severity: medium
Commit: 9f07374e9eb2398e...

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A memory corruption issue was addressed with improved state management….


CVE-2026-43794

Bugzilla: 317317
Component: WebKit
Class: LogicError
Severity: medium
Commit: 4a92fe2ccba1be5f...

Processing maliciously crafted web content may lead to memory corruption

RCA: A memory corruption issue was addressed with improved memory handling….


CVE-2026-64787

Bugzilla: 313703
Component: WebCore
Class: UAF
Severity: medium
Commit: cb83583e5f4d9553...

Processing maliciously crafted web content may lead to an unexpected process termination

RCA: trustedTypeCompliantString executes arbitrary JavaScript via Trusted Types policy callbacks. The callers in Document::parseHTMLUnsafe, Document::write, and Document::execCommand passed a raw `…


CVE-2026-64778

Bugzilla: 322124
Component: WebKit
Class: LogicError
Severity: medium

Visiting a maliciously crafted website may leak sensitive data

RCA: The issue was addressed with improved checks….


CVE-2026-64779

Bugzilla: 321485
Component: WebKit
Class: LogicError
Severity: medium

Processing maliciously crafted web content may lead to an unexpected Safari crash

RCA: A memory corruption vulnerability was addressed with improved locking….