Apple and Red Hat disclosed CVE-2026-43732, a moderate-severity path handling flaw in WebKit and WebKitGTK that can let maliciously crafted web content disclose sensitive user information. The issue is tracked as CWE-22 and was addressed through improved validation; Red Hat assigned it a CVSS v3.1 score of 6.5 and linked the Linux-side issue to WebKitGTK advisory WSA-2026-0004 and WebKit bug 313085.
Fixes were released across Apple platforms including Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS, affecting versions before Safari 26.5.2, iOS and iPadOS 26.5.2, macOS Tahoe 26.5.2, and tvOS, visionOS, and watchOS 26.6. Red Hat said patched packages are available for multiple RHEL 7, 8, and 9 product streams, including EUS, SAP, and Extended Lifecycle Support variants, while RHEL 6 packages are outside support scope.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat last modified its CVE entry for CVE-2026-43732, maintaining fix and severity information for affected RHEL offerings. The entry notes available fixes and out-of-support scope for RHEL 6 packages.
Red Hat issued RHSA-2026:42088 for Red Hat Enterprise Linux 8 and RHSA-2026:42062 for Red Hat Enterprise Linux 9, marking CVE-2026-43732 as fixed in those product streams. The fixes address the WebKitGTK path handling issue through improved validation.
Red Hat created Bugzilla bug 2500536 to track CVE-2026-43732 under its Security Response product. The bug records the issue as affecting WebKitGTK on Linux and notes medium severity and priority.
Red Hat published CVE-2026-43732 in its CVE Database and classified it as a moderate-severity WebKitGTK vulnerability. Red Hat mapped the issue to CWE-22 and described the impact as disclosure of sensitive user information via malicious web content.
The CVE record for CVE-2026-43732 was published, describing an Apple path handling issue that could let maliciously crafted web content disclose sensitive user information. The record states Apple addressed the flaw with improved validation.
Red Hat issued RHSA-2026:58564 for Red Hat Enterprise Linux 7 Extended Lifecycle Support and RHSA-2026:58550 for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. These advisories mark CVE-2026-43732 as fixed in the remaining listed supported RHEL streams.
Red Hat issued RHSA-2026:57348 to fix CVE-2026-43732 in Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On. The advisory covers the affected webkit2gtk3 component in both offerings.
Red Hat issued RHSA-2026:54634 for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions and RHSA-2026:54572 for Red Hat Enterprise Linux 9.6 Extended Update Support. Both advisories mark CVE-2026-43732 as fixed in those RHEL 9 variants.
The CVE record for CVE-2026-43732 was updated after publication. It lists Apple fixes across Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.