Apple WebKit Processing Files Vulnerability Leading to App Termination or Arbitrary Code Execution

Vulnerability

A vulnerability in WebKit, the engine powering Safari and other applications, allows for processing maliciously crafted files, which can lead to unexpected app termination or arbitrary code execution. This issue affects multiple Apple platforms, including macOS Sonoma 14.5, iOS 17.5, iPadOS 17.5, watchOS 10.5, tvOS 17.5, and visionOS 1.2. The vulnerability arises from an out-of-bounds write issue that was addressed with improved input validation and memory handling.

Impact

Exploitation of this vulnerability can cause unexpected application termination or allow for arbitrary code execution, potentially with elevated privileges, depending on the context.

Remediation

Users can update to the latest versions of macOS, iOS, iPadOS, watchOS, tvOS, or visionOS to address this vulnerability. Instructions for updating can be found on the Apple Support website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
7.5
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.