Apple and Red Hat disclosed CVE-2026-43740, a moderate-severity use-after-free vulnerability in WebKit-derived web content processing that can let maliciously crafted pages disclose process memory. The flaw stems from improper memory handling, is mapped to CWE-416, and requires user interaction but no privileges, with Red Hat assigning a CVSS v3.1 score of 6.5 and noting a network attack vector and low attack complexity.
Apple said the issue was fixed in Safari 26.5.2, iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. Red Hat said affected WebKitGTK packages were addressed through multiple advisories for Red Hat Enterprise Linux 7, 8, and 9 product streams, while RHEL 6 packages are outside support scope and should be assumed affected.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2026:58564 for Red Hat Enterprise Linux 7 Extended Lifecycle Support and RHSA-2026:58550 for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, marking those streams fixed for CVE-2026-43740.
Red Hat issued RHSA-2026:57348 for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On, marking both streams fixed for CVE-2026-43740.
Red Hat issued RHSA-2026:54634 for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions and RHSA-2026:54572 for Red Hat Enterprise Linux 9.6 Extended Update Support, marking both streams fixed for CVE-2026-43740.
Red Hat last modified its CVE-2026-43740 record, reflecting updated tracking information for the WebKitGTK vulnerability.
Red Hat issued RHSA-2026:42088 for Red Hat Enterprise Linux 8 and RHSA-2026:42062 for Red Hat Enterprise Linux 9, marking those product streams fixed for CVE-2026-43740.
Red Hat published its CVE-2026-43740 entry for a moderate-severity use-after-free flaw in WebKitGTK that can disclose process memory when processing malicious web content. Red Hat mapped the issue to CWE-416 and assigned CVSS 6.5.
Apple, as CNA, published CVE-2026-43740 describing an improper memory handling flaw that can let maliciously crafted web content disclose process memory. The record notes fixes across Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS releases.
The CVE record for CVE-2026-43740 was updated after its initial publication. The entry continued to identify Apple as CNA and retained the cross-platform fix information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.