Red Hat disclosed fixes for CVE-2026-43731, an Important-severity WebKitGTK use-after-free vulnerability that can be triggered when a user processes maliciously crafted web content. The flaw, tracked as CWE-416, can lead to memory corruption and may enable unauthorized code execution, memory disclosure, or application crashes; Red Hat assigned it a CVSS 8.8 score and linked it to WebKitGTK advisory WSA-2026-0004 and WebKit bug 314115.
The issue originated in Apple's WebKit codebase, where Apple said improved memory management fixed the bug across Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Red Hat said remediation is available through security errata for multiple RHEL 7, 8, and 9 offerings, including standard, EUS, SAP, and long-life support variants, while RHEL 6 is out of support scope and should be assumed affected if the vulnerable packages are present.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2026:42088 for RHEL 8 and RHSA-2026:42062 for RHEL 9 to address CVE-2026-43731 in webkit2gtk3.
Red Hat tracked CVE-2026-43731 as Bugzilla bug 2500535 after it was reported by OSIDB Bzimport. The bug classified the Linux WebKitGTK issue as a high-severity vulnerability.
Red Hat states that CVE-2026-43731 became public on July 10, 2026. The flaw affects WebKitGTK and can lead to memory corruption, including possible code execution, memory disclosure, or crashes.
The CVE record for CVE-2026-43731 was published, describing an Apple use-after-free flaw in processing maliciously crafted web content that can lead to memory corruption.
Red Hat issued RHSA-2026:58564 for RHEL 7 Extended Lifecycle Support and RHSA-2026:58550 for RHEL 9.2 Update Services for SAP Solutions to address CVE-2026-43731.
Red Hat issued RHSA-2026:57348 to fix CVE-2026-43731 for both RHEL 8.4 Advanced Mission Critical Update Support and RHEL 8.4 Extended Update Support Long-Life Add-On.
The CVE record for CVE-2026-43731 was updated, reflecting Apple fix information across Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.