Executive brief
A critical vulnerability exists in WebKit, the engine that powers the Safari web browser and displays web content across Apple devices like iPhones, iPads, and Macs. By tricking a user into visiting a specially crafted website, an attacker could take control of the device or run unauthorized programs. This flaw has been used in highly targeted attacks against specific individuals, making immediate updates essential to protect sensitive data and device integrity.
Technical details
A use-after-free (UAF) vulnerability exists in the WebKit component of multiple Apple operating systems. The flaw is triggered during the processing of maliciously crafted web content, specifically within HTML parsing routines. An unauthenticated remote attacker can achieve arbitrary code execution (ACE) if a user visits a malicious webpage. Apple addressed the issue by improving memory management. This vulnerability is notable for its confirmed exploitation in the wild against targeted individuals. Patches are available in Safari 26.2, iOS/iPadOS 18.7.3, and various version 26.2 releases for macOS, tvOS, visionOS, and watchOS.
Affected products
- Apple Safari < 26.2
- Apple iOS < 18.7.3, 26.0 - 26.2
- Apple iPadOS < 18.7.3, 26.0 - 26.2
- Apple macOS < 26.2
- Apple tvOS < 26.2
- Apple visionOS < 26.2
- Apple watchOS < 26.2
Timeline
- 2025-12-15: disclosed
- 2025-12-15: kev added: Added to CISA KEV catalog
- 2025-12-15: patched: Fixed in Safari 26.2 and various OS updates
- 2025-12-15: exploited: Reported as exploited in targeted attacks