Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Apple WebKit Remote Code Execution Vulnerability

Vulnerability

A logic vulnerability allowing remote code execution has been identified in the WebKit component of Apple iOS, iPadOS, and macOS. This issue arises from insufficient restrictions in the handling of web content, which could be exploited by a remote attacker. The vulnerability affects WebKitGTK, the version of WebKit used in GTK applications, including those on macOS and iOS. The flaw has been addressed in multiple Apple software updates, including macOS Big Sur 11.2, Security Update 2021-001 for Catalina, Security Update 2021-001 for Mojave, iOS 14.4, and iPadOS 14.4.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected system.

Remediation

Users can update to the latest version of macOS or iOS to address this vulnerability. Instructions for updating can be found on the Apple Support website.

Added: May 15, 2026, 10:36 AM
Updated: May 15, 2026, 10:36 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
7.5
exploitability
6.4
remediation
7.7
relevance
0.0
threat
8.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.