Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Apple WebKit Integer Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability exists in the WebKit component of multiple Apple products, including iOS, iPadOS, macOS Monterey, tvOS, and watchOS. This vulnerability is an integer overflow that was introduced through the processing of maliciously crafted web content. The issue has been addressed with improved input validation. However, the vulnerability could be exploited to execute arbitrary code on the affected device.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution on the affected device.

Remediation

Users can update to the latest versions of the affected operating systems and applications. Instructions for updating can be found on the Apple Support website. For specific guidance on updating WebKitGTK or WPE WebKit, refer to the respective security advisory pages.

Added: May 15, 2026, 11:34 AM
Updated: May 15, 2026, 11:34 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
7.5
exploitability
5.3
remediation
7.7
relevance
0.0
threat
8.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.