Apple and Red Hat disclosed CVE-2026-43663, a moderate-severity CWE-416 use-after-free flaw in WebKit/WebKitGTK caused by improper memory handling when processing maliciously crafted web content. The vulnerability can be triggered over the network with low attack complexity and no privileges, but it requires user interaction; vendors say successful exploitation can cause an unexpected process crash, creating a denial-of-service condition and potentially broader memory-corruption risks in some scenarios.
Apple said it fixed the issue across Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS, while Red Hat reported remediation for multiple RHEL 7, 8, and 9 product streams through security errata and related Bugzilla tracking. Red Hat assigned the flaw a CVSS v3 score of 6.5 and noted that some older RHEL 6 packages containing affected components fall outside support scope; the fix was described as improved memory handling in WebKitGTK.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat last modified its CVE-2026-43663 customer portal entry, reflecting updated vulnerability and remediation information. The portal entry continued to track affected and fixed product streams for the WebKitGTK flaw.
Red Hat marked CVE-2026-43663 as fixed for Red Hat Enterprise Linux 8 in RHSA-2026:42088 and for Red Hat Enterprise Linux 9 in RHSA-2026:42062. These were the first explicitly dated Red Hat product fixes listed for the vulnerability.
Red Hat created Bugzilla record 2500520 to track CVE-2026-43663 as a Linux security vulnerability affecting WebKitGTK. The bug describes maliciously crafted web content causing an unexpected process crash and notes the issue was addressed through improved memory handling.
Red Hat published its customer portal entry for CVE-2026-43663, classifying the WebKitGTK flaw as a moderate-severity use-after-free vulnerability with a CVSS v3 score of 6.5. The entry linked Bugzilla 2500520, WebKit bug 312781, and advisory WSA-2026-0004.
Apple, acting as CNA, published the CVE record for CVE-2026-43663 describing improper memory handling in WebKit-related content processing that can cause an unexpected process crash. The record also notes Apple had addressed the issue with improved memory handling across multiple Apple platforms.
Red Hat listed CVE-2026-43663 as fixed for Red Hat Enterprise Linux 7 Extended Lifecycle Support in RHSA-2026:58564 and for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions in RHSA-2026:58550. These advisories further extended fix availability across legacy and SAP-focused product streams.
Red Hat listed RHSA-2026:57348 as fixing CVE-2026-43663 for both Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On. This expanded remediation coverage for older supported RHEL 8.4 streams.
The CVE record for CVE-2026-43663 was updated after its initial publication. The update preserved Apple as CNA and continued to reference the affected Apple products and fixed versions.
Red Hat listed CVE-2026-43663 as fixed for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions in RHSA-2026:54634 and for Red Hat Enterprise Linux 9.6 Extended Update Support in RHSA-2026:54572. Both fixes were explicitly dated the same day.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.