Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Apple WebKit Sandbox Escape Vulnerability

Vulnerability

A vulnerability in WebKit, the engine used by Apple Safari and other applications for HTML processing, allows remote attackers to escape the Web Content sandbox. This issue affects multiple Apple products, including iOS, iPadOS, macOS, tvOS, watchOS, and Safari. The vulnerability was addressed with improved bounds checks, but not before it was reported to have been actively exploited.

Impact

Exploitation of this vulnerability allows a remote attacker to break out of the Web Content sandbox, potentially leading to unauthorized access or manipulation of system resources or data.

Remediation

Users can update to the latest versions of the affected Apple products. Specific update instructions can be found on the Apple security updates page.

Added: May 15, 2026, 11:17 AM
Updated: May 15, 2026, 11:17 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
10.0
exploitability
5.9
remediation
7.7
relevance
0.0
threat
8.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.