Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Apple iOS WebKit Use-After-Free Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A use-after-free vulnerability has been identified in the WebKit component of Apple iOS. This issue affects iOS devices including the iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad mini 2, iPad mini 3, and iPod touch (6th generation). The vulnerability arises from a memory corruption issue in the ASN.1 decoder, which was addressed by removing the vulnerable code. However, the vulnerability could still be exploited by processing maliciously crafted web content, leading to arbitrary code execution. Apple is aware of reports suggesting that this issue may have been actively exploited.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution on the affected device.

Remediation

Users can update to iOS 12.5.4 to address this vulnerability.

Added: May 15, 2026, 10:37 AM
Updated: May 15, 2026, 10:37 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.3
remediation
0.0
relevance
0.0
threat
8.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.