Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Apple WebKit Out-of-Bounds Read Vulnerability Allowing Sensitive Information Disclosure

Vulnerability

A vulnerability in WebKit, the rendering engine used by Safari and other applications, has been identified. This issue involves an out-of-bounds read that could lead to the unintentional disclosure of sensitive information when processing maliciously crafted web content. The vulnerability is present in multiple Apple products, including iOS, iPadOS, macOS, and Safari, and affects several different versions and ranges. Notably, there are reports suggesting that this vulnerability may have been actively exploited in the wild, particularly in versions of iOS prior to 16.7.1.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive information, potentially leading to further exploitation or attacks.

Remediation

Users can update to the latest versions of iOS, iPadOS, macOS, and Safari. Instructions for updating these Apple products are available on the Apple Support website.

Added: May 15, 2026, 11:31 AM
Updated: May 15, 2026, 11:31 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.9
remediation
7.7
relevance
0.0
threat
8.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.