Red Hat disclosed CVE-2026-43742, a moderate-severity use-after-free flaw in WebKitGTK caused by improper memory management when handling maliciously crafted web content. The bug can trigger an unexpected process crash and is tracked under CWE-416 with a CVSS v3.1 score of 6.5; Red Hat noted that, in some circumstances, the weakness could also lead to memory corruption, memory disclosure, or potentially arbitrary code execution. The issue was addressed through improved memory management and aligns with Apple’s upstream description of the same vulnerability affecting WebKit-based platforms.
Red Hat linked fixes for affected Red Hat Enterprise Linux 7, 8, and 9 offerings to multiple RHSA advisories, while packages in RHEL 6 containing pywebkitgtk and webkitgtk are out of support scope and should be assumed affected. The flaw is also referenced in WebKitGTK Security Advisory WSA-2026-0004 and WebKit bug 315161, and Apple’s CVE record says the same crafted-content issue affected Safari and several Apple operating systems before their respective patched versions.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat recorded Bugzilla issue 2500539 for CVE-2026-43742 under its Security Response product. The bug tracked the WebKitGTK use-after-free flaw as medium severity and medium priority on Linux.
Red Hat published its CVE entry for CVE-2026-43742, describing a moderate-severity WebKitGTK use-after-free vulnerability caused by improper memory management when processing maliciously crafted web content. Red Hat linked the issue to Bugzilla 2500539, WebKit bug 315161, and WebKitGTK advisory WSA-2026-0004.
Apple published CVE-2026-43742 for a use-after-free issue in web content processing that could cause an unexpected process crash. The CVE record states the flaw was addressed with improved memory management and fixed in Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS releases.
The CVE record for CVE-2026-43742 was updated after its initial publication. The update retained Apple as CNA and continued to reference the fixed versions across affected Apple products.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.