Apple and Red Hat disclosed CVE-2026-43720, a use-after-free vulnerability in WebKit and WebKitGTK that can be triggered when a user processes maliciously crafted web content. The flaw, mapped to CWE-416, stems from improper memory management and can cause an unexpected browser or process crash, including Safari crashes on Apple platforms. Red Hat rated the issue moderate with a CVSS v3.1 score of 6.5, noting that exploitation requires user interaction and primarily affects availability.
Fixes were released across Apple products including Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS, while Red Hat published remediation for affected WebKitGTK packages in multiple Red Hat Enterprise Linux 7, 8, and 9 offerings. Red Hat said RHEL 6 packages are outside support scope and should be assumed affected, and linked the issue to WebKit advisory WSA-2026-0004 and upstream bug 313175.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat tracked CVE-2026-43720 as Bugzilla bug 2500530 under its Security Response product. The bug classified the WebKitGTK flaw as a medium-severity, medium-priority vulnerability on Linux.
Red Hat published its CVE-2026-43720 entry, rating the WebKitGTK use-after-free vulnerability as Moderate severity with a CVSS v3.1 score of 6.5. Red Hat also listed fixed RHEL 7, 8, and 9 offerings and marked certain RHEL 6 packages as out of support scope.
Apple published CVE-2026-43720, describing a use-after-free issue in WebKit processing of maliciously crafted web content that can cause an unexpected Safari crash. The record notes the issue was addressed through improved memory management.
The CVE record for CVE-2026-43720 was updated after its initial publication. The record continued to reference fixes across Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.