Apple and Red Hat disclosed CVE-2026-43727, a use-after-free vulnerability in WebKit and WebKitGTK that can be triggered by maliciously crafted web content and cause an unexpected browser or process crash. The flaw is attributed to improper memory management and is tracked as CWE-416; Red Hat scored it CVSS 6.5 and classified it as moderate severity, with impact focused on availability rather than confirmed code execution.
Apple said the issue was fixed in Safari 26.5.2, iOS 18.7.10 and 26.5.2, iPadOS 18.7.10 and 26.5.2, macOS Tahoe 26.5.2, visionOS 26.6, and watchOS 26.6. Red Hat published fixes through multiple security errata for affected Red Hat Enterprise Linux 7, 8, and 9 offerings, while noting that Red Hat Enterprise Linux 6 packages are outside support scope and should be assumed affected if WebKitGTK is present.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat last modified its CVE-2026-43727 customer portal entry. The entry continued to document affected and fixed RHEL offerings and mapped the flaw to CWE-416.
Red Hat released fixes for CVE-2026-43727 for Red Hat Enterprise Linux 8 via RHSA-2026:42088 and for Red Hat Enterprise Linux 9 via RHSA-2026:42062. These advisories remediated the WebKitGTK use-after-free issue on the main supported RHEL 8 and 9 streams.
Red Hat tracked the issue internally as Bug 2500534 under Security Response. The bug was reported by OSIDB Bzimport and classified as a vulnerability affecting Linux with medium priority and severity.
Red Hat published its customer portal entry for CVE-2026-43727, rating the WebKitGTK flaw Moderate severity and assigning CVSS 6.5. Red Hat described the issue as a use-after-free caused by improper memory management that could lead to an unexpected process crash.
The CVE record for CVE-2026-43727 was published with Apple listed as the CNA. The record described a use-after-free issue in WebKit-related software that could let maliciously crafted web content cause an unexpected Safari crash.
Red Hat issued RHSA-2026:58564 for Red Hat Enterprise Linux 7 Extended Lifecycle Support and RHSA-2026:58550 for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. These advisories added fixes for CVE-2026-43727 to remaining listed supported channels.
Red Hat shipped RHSA-2026:57348 to fix CVE-2026-43727 for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On. This expanded coverage of the WebKitGTK fix to additional RHEL 8 support variants.
The CVE record for CVE-2026-43727 was updated. The record includes Apple support references and lists CISA-ADP as an authorized data publisher.
Red Hat released RHSA-2026:54634 for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions and RHSA-2026:54572 for Red Hat Enterprise Linux 9.6 Extended Update Support. These advisories extended remediation of CVE-2026-43727 to additional RHEL 9 support channels.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.