Apple WebKit Race Condition Vulnerability Leading to Process Crash

Vulnerability

A race condition vulnerability has been identified in the WebKit component of Apple software, including WebKit itself, Safari, and various operating systems such as iOS, iPadOS, macOS Tahoe, watchOS, tvOS, and visionOS. This vulnerability allows processing of maliciously crafted web content, which may result in an unexpected crash of the affected process. The issue has been addressed with improved state handling.

Impact

Exploitation of this vulnerability can cause an unexpected process crash, disrupting normal application or system functionality. Additionally, in the context of WebKit, this vulnerability has been associated with a use-after-free issue that could lead to arbitrary code execution, according to reports of exploitation against targeted individuals on earlier iOS versions.

Remediation

Users can update to the latest versions of watchOS, Safari, iOS, iPadOS, macOS Tahoe, tvOS, or visionOS to address this vulnerability. Instructions for updating can be found on the Apple Support website.

Added: Dec 17, 2025, 9:35 PM
Updated: Dec 17, 2025, 10:32 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
4.0
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.