Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Apple WebKit Arbitrary Code Execution Vulnerability

Vulnerability

A vulnerability in the WebKit component of multiple Apple products, including iOS, iPadOS, macOS, and Safari, allows for arbitrary code execution. This issue arises from a use-after-free vulnerability that can be exploited by processing maliciously crafted web content. Apple has acknowledged reports of this vulnerability being actively exploited in the wild on versions of iOS prior to 16.7.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution on the affected system.

Remediation

This vulnerability has been fixed in macOS Sonoma 14. Users should upgrade to this version. For iOS and iPadOS, the vulnerability is addressed in version 17.0.1. Safari users should upgrade to version 16.6.1.

Added: May 15, 2026, 11:26 AM
Updated: May 15, 2026, 11:26 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
7.5
exploitability
5.3
remediation
7.7
relevance
0.0
threat
8.5
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.