Apple and Red Hat disclosed CVE-2026-43725, an improper input validation flaw in WebKit and WebKitGTK that allows a malicious website to cause restricted web content to be processed outside the browser sandbox. Red Hat rates the issue Important with a CVSS v3.1 score of 7.1 and maps it to CWE-20, warning that successful exploitation could affect confidentiality, integrity, and availability by exposing restricted resources.
The vulnerability was addressed through improved input validation and fixed across Apple platforms including Safari, iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS, while Red Hat published remediation through multiple advisories for supported RHEL 7, 8, and 9 offerings. Red Hat's Bugzilla tracking links the issue to WebKit bug 312832 and WebKitGTK advisory WSA-2026-0004, and notes that RHEL 6 packages are outside support scope and should be assumed affected.

See affected versions and whether adversaries are exploiting it.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat released advisory RHSA-2026:42062 to remediate CVE-2026-43725 in Red Hat Enterprise Linux 9. The flaw could allow restricted web content to be processed outside the sandbox.
Red Hat released advisory RHSA-2026:42088 to fix CVE-2026-43725 in Red Hat Enterprise Linux 8. The issue was addressed through improved input validation in WebKitGTK.
Red Hat Bugzilla bug 2500532 was reported to track CVE-2026-43725. The bug classified the WebKitGTK issue as a high-severity vulnerability affecting Linux.
The CVE record for CVE-2026-43725 was published with Apple as the CNA. The record describes an improper input validation flaw that could let a malicious website process restricted web content outside the sandbox.
Red Hat issued RHSA-2026:58564 to address CVE-2026-43725 in Red Hat Enterprise Linux 7 Extended Lifecycle Support.
Red Hat issued RHSA-2026:58550 to fix CVE-2026-43725 in Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.
Red Hat released RHSA-2026:54572 to remediate CVE-2026-43725 in Red Hat Enterprise Linux 9.6 Extended Update Support.
Red Hat released RHSA-2026:54634 to address CVE-2026-43725 in Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions.
Red Hat issued RHSA-2026:57348 to fix CVE-2026-43725 for both Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On.
The CVE record for CVE-2026-43725 was updated after its initial publication. The record continued to reference Apple fixes across Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.