Medium CVSS 6.5 webkit OOB

Overview

Medium
Severity
6.5
CVSS
No
Exploited ITW
Embargoed
Fix Status
DescriptionProcessing maliciously crafted web content may lead to an unexpected Safari crash
ComponentWebKit
Bug ClassOOB
Tracker317231
CWECWE-125, CWE-787 (Out-of-bounds read, Out-of-bounds write)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA KEVNot listed
CreditedTommy DeVoss from Braze Security Team (@thedawgyg), Mateusz Krzywicki (iVerify.io), dr3dd
Disclosed2026-06-29

Fix not yet public

No public source fix for this bug has been identified on the main branch yet — it is embargoed or not yet disclosed. Root-cause analysis is withheld until the fix commit is available.

Original Bug Report

The reporter's bug is still restricted on the tracker.