ZeroHour

Vulnerabilities

24 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-43343
+1 in the same advisory: …43342
The issue was addressed with improved memory handling.

The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.

NVD description · AI analysis pending
9.8<1%
  • apple safari
  • apple ipados
  • apple iphone os
  • +1 more
CVE-2025-31277
Buffer Overflow in Apple WebKit (Safari, iOS/iPadOS, macOS, WebKitGTK, WPE)

CVE-2025-31277 is a memory-handling flaw (buffer overflow, CWE-119/CWE-120) in Apple's WebKit engine, the component that renders web content in Safari and in webviews across Apple platforms. It is triggered when a user processes maliciously crafted web content, typically by visiting an attacker-controlled page, causing memory corruption that can compromise the rendering process, with CVSS 3.1 scoring high impact to confidentiality, integrity and availability (8.8) via a network vector requiring user interaction but no privileges. Everyone running WebKit is affected: Safari users and devices on iOS/iPadOS, macOS Sequoia, tvOS, visionOS and watchOS prior to the fixed releases, plus Linux users of WebKitGTK and WPE WebKit as shipped with Red Hat Enterprise Linux (including the AUS and ELS channels). Exploitation is confirmed in the wild: CISA added the bug to its Known Exploited Vulnerabilities catalog on 2026-03-20 (ransomware linkage unknown) with a BOD 22-01 remediation deadline of 2026-04-03, and contemporaneous reporting describes 'DarkSword', an iOS exploit kit chaining multiple Apple flaws, reportedly including zero-days, in global attacks, possibly including this bug. No public proof-of-concept is known, and fixes shipped in Safari 18.6, iOS/iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6 and watchOS 11.6.

Do: Upgrade Safari to 18.6 or later and apply the corresponding OS updates: iOS/iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6 and watchOS 11.6; on Red Hat Enterprise Linux (including AUS/ELS) install Red Hat's updated WebKitGTK/WPE WebKit packages. Organizations subject to CISA BOD 22-01 must patch or mitigate by the April 3, 2026 deadline. Until patched, restrict WebKit-based browsing and webviews on affected devices to trusted content, since exploitation requires loading maliciously crafted web content.

8.82% KEV
  • Apple Safari all versions prior to 18.6 (fixed in 18.6)
  • Apple iOS / iPhone OS all versions prior to 18.6 (fixed in 18.6)
  • Apple iPadOS all versions prior to 18.6 (fixed in 18.6)
  • +7 more
mass≈1 billion+ users/devices (WebKit ships on essentially every active iPhone, iPad, Mac, Apple TV, Apple Watch and Vision Pro; the RHEL WebKitGTK/WPE WebKit…
CVE-2025-6558
Actively Exploited Input Validation Flaw in Chrome ANGLE/GPU Allows Sandbox Escape

CVE-2025-6558 is an improper input validation flaw (CWE-20) in the ANGLE graphics translation layer and GPU processing code of Google Chrome/Chromium prior to version 138.0.7204.157. A remote attacker can trigger it by convincing a user to open a crafted HTML page (user interaction is required), and successful exploitation potentially enables a sandbox escape from the browser's renderer with high impact on confidentiality, integrity, and availability. Per the CPE data, exposure extends beyond Chrome to Debian's Chromium package, Apple Safari and its operating systems (iOS, iPadOS, macOS, visionOS, watchOS), and the WebKitGTK and WPE WebKit ports, consistent with the shared ANGLE/WebKit code. Google fixed the issue in Chrome 138.0.7204.157, and CISA added the flaw to the KEV catalog on 2025-07-22, confirming active exploitation in the wild (ransomware use: unknown). EPSS assigns a 9.6% probability of exploitation within 30 days (95th percentile); no public proof-of-concept is known.

Do: Upgrade Google Chrome/Chromium to 138.0.7204.157 or later immediately, as the flaw is being actively exploited and is KEV-listed. Debian users should install the distribution's patched Chromium package, and operators of Apple platforms, WebKitGTK, or WPE WebKit deployments should apply the corresponding vendor security updates. Federal agencies must apply vendor mitigations per BOD 22-01 within the required timeframe or discontinue use if mitigations are unavailable.

8.810% KEV
  • Google Chrome prior to 138.0.7204.157
  • Google Chromium prior to 138.0.7204.157
  • Debian Linux (Chromium package)
  • +8 more
massbillions of users/installations (Chrome and Chromium-derived browsers)
CVE-2024-27834
The issue was addressed with improved checks.

The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

NVD description · AI analysis pending
5.5<1%
  • apple safari
  • apple ipados
  • apple iphone os
  • +1 more
CVE-2024-23263
+3 in the same advisory: …23284 …23280 …23254
A logic issue was addressed with improved validation.

A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

NVD description · AI analysis pending
6.51%
  • apple safari
  • apple ipados
  • apple iphone os
  • +1 more
CVE-2023-42843
An inconsistent user interface issue was addressed with improved state management.

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.

NVD description · AI analysis pending
4.3<1%
  • apple safari
  • apple ipad os
  • apple iphone os
  • +1 more
CVE-2023-40397
+1 in the same advisory: …32370
The issue was addressed with improved checks.

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. A remote attacker may be able to cause arbitrary javascript code execution.

NVD description · AI analysis pending
9.8
group max
2%
  • apple macos
  • apple webkitgtk
  • apple wpe webkit
CVE-2023-28198
A use-after-free issue was addressed with improved memory management.

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Processing web content may lead to arbitrary code execution.

NVD description · AI analysis pending
8.8<1%
  • apple ipados
  • apple iphone os
  • apple macos
  • +1 more
CVE-2019-8720
Memory Corruption in WebKitGTK/WPE WebKit Enables Arbitrary Code Execution

CVE-2019-8720 is a memory corruption flaw (CWE-119) in the WebKit engine as packaged in WebKitGTK and WPE WebKit, in which multiple memory-handling errors can be triggered by processing maliciously crafted web content. An attacker who gets a user to load attacker-controlled HTML — for example through an application that uses WebKitGTK to render email, feeds, or other web content — can corrupt memory and potentially execute arbitrary code with the privileges of that application. The CVSS 3.1 score of 8.8 (high) reflects that the attack path is network-based, requires no privileges but does require user interaction, and yields high impact on confidentiality, integrity, and availability. Users of WebKitGTK and WPE WebKit, including the packages shipped with Red Hat Enterprise Linux and its desktop, EUS, and architecture-specific variants, are affected. CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2022-05-23, indicating known exploitation in the wild; no public proof-of-concept is known, and EPSS estimates a 1.6% probability of exploitation in the next 30 days.

Do: Apply updated WebKitGTK/WPE WebKit packages per vendor instructions — for Red Hat Enterprise Linux, install the corrected packages from Red Hat security errata for your release — and prioritize systems where users view untrusted HTML, such as mail, feed, or desktop applications that embed WebKitGTK. As an interim mitigation, avoid rendering untrusted web content in applications that use WebKitGTK. Inventory hosts for webkitgtk/webkit2gtk packages and confirm they are on the patched release for your Red Hat Enterprise Linux version.

8.82% KEV
  • WebKitGTK
  • WPE WebKit
  • Red Hat Enterprise Linux
  • +9 more
massplausibly millions of Linux installations (WebKitGTK ships within Red Hat Enterprise Linux and GNOME desktop stacks)
CVE-2022-32893
Out-of-Bounds Write in Apple WebKit (iOS/macOS/Safari) Enables RCE

CVE-2022-32893 is an out-of-bounds write flaw (CWE-787) in Apple's WebKit browser engine, caused by insufficient bounds checking. It is triggered when a device processes maliciously crafted web content, meaning a user can be attacked simply by loading an attacker-controlled webpage. A successful exploit allows arbitrary code execution on the victim's device, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Affected users include anyone running iOS/iPadOS before 15.6.1, macOS Monterey before 12.5.1, or Safari before 15.6.1, as well as consumers of WebKitGTK and WPE WebKit shipped in Fedora and Debian. Apple confirmed the issue was being actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-18; EPSS estimates a 9.9% probability of exploitation in the next 30 days (95th percentile), while no public PoC is known.

Do: Immediately update to iOS 15.6.1, iPadOS 15.6.1, macOS Monterey 12.5.1, and Safari 15.6.1; per vendor reporting, Apple also released updates for older iPhone models, and users of devices running the iOS 15.7 beta should apply 15.6.1. Fedora and Debian users should install the patched WebKitGTK/WPE WebKit packages from their distribution's advisories. Because exploitation requires only loading malicious web content, there is no reliable workaround — prioritize patching on all endpoints that browse web content, and treat unpatched Apple devices as actively targeted.

8.810% KEV
  • Apple iPhone OS (iOS) all versions prior to 15.6.1
  • Apple iPadOS all versions prior to 15.6.1
  • Apple macOS Monterey prior to 12.5.1
  • +5 more
masshundreds of millions of devices (Apple's active iPhone/Mac installed base plus Safari/WebKit users)
CVE-2022-2294
Heap Buffer Overflow in Google Chrome WebRTC Exploited in the Wild

CVE-2022-2294 is a heap buffer overflow (out-of-bounds write, CWE-787) in the WebRTC component used by Google Chrome. A remote attacker can trigger the flaw by luring a user to a crafted HTML page, and successful exploitation allows heap corruption with potential arbitrary code execution (CVSS 3.1: 8.8, high impact on confidentiality, integrity and availability). It affects Chrome prior to 103.0.5060.114 and, because the vulnerable code path resides in the shared WebRTC/WebKit component, it also affects Apple's iPhone OS, iPadOS, macOS/Mac OS X, tvOS and watchOS, WebKitGTK, WPE WebKit, Fedora and Extra Packages for Enterprise Linux (EPEL), and the WebRTC project library itself. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-25 with known ransomware use, and reporting indicates mercenary spyware operators used it as a Chrome zero-day; EPSS places its 30-day exploitation probability at 70.5%. Google fixed the flaw in Chrome 103.0.5060.114, and Apple and the WebKit/WPE maintainers issued their own security updates for affected products.

Do: Upgrade Google Chrome to 103.0.5060.114 or later on all managed and personal endpoints immediately. Apply Apple's released security updates for iPhone OS, iPadOS, macOS, tvOS and watchOS, and updated WebKitGTK, WPE WebKit and Fedora/EPEL packages for WebKit-based deployments. Given the CISA KEV listing, known ransomware use and 70.5% EPSS, prioritize patching and hunt for signs of exploitation (crafted-page lures and any linked spyware or ransomware activity) across browsers and WebKit applications.

8.870% KEV ransomware
  • google Chrome prior to 103.0.5060.114
  • webrtc project WebRTC affected component library per CISA; fixed in updated releases
  • apple iPhone OS affected releases; fixed via Apple security updates
  • +8 more
mass≈3+ billion Chrome users worldwide, plus additional users of Apple WebKit devices, WebKitGTK, WPE WebKit and Fedora/EPEL browser packages
CVE-2021-42762
BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into th

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.

NVD description · AI analysis pending
5.3<1% PoC
  • webkitgtk webkitgtk
  • webkitgtk wpe webkit
  • webkitgtk fedora
  • +1 more
CVE-2021-30952
CVE-2021-30952: Integer Overflow in Apple Safari/WebKit Allows Arbitrary Code Execution

CVE-2021-30952 is an integer overflow (CWE-190) in the WebKit web engine used across Apple's platforms — the same engine shipped as WebKitGTK and WPE WebKit on Linux — which Apple addressed with improved input validation. An attacker triggers it by persuading a user to process maliciously crafted web content, such as loading an attacker-controlled web page, and successful exploitation leads to arbitrary code execution on the victim's device (CVSS 3.1: 7.8 high, with a local attack vector requiring user interaction). All users of unpatched affected platforms are exposed: iOS/iPadOS before 15.2, macOS Monterey before 12.1, Safari before 15.2, tvOS before 15.2, and watchOS before 8.3, plus Fedora/Debian systems running unpatched WebKitGTK/WPE WebKit. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-03-05 (ransomware use: unknown), and Google threat intelligence documented it as part of the 'Coruna' iOS exploit kit — 23 exploits across five chains, used for financial crime and targeting devices on older iOS versions such as iOS 13. EPSS assigns a 7.0% probability of exploitation within 30 days (94th percentile).

Do: Upgrade to iOS/iPadOS 15.2, macOS Monterey 12.1, Safari 15.2, tvOS 15.2, and watchOS 8.3; devices on older iOS branches (e.g., iOS 13, targeted by the Coruna exploit kit) should immediately apply Apple's emergency fixes for those versions. On Fedora and Debian, pull the latest WebKitGTK/WPE WebKit security updates through the distro package channels. Federal agencies must meet the BOD 22-01 remediation deadline for this KEV entry, and should inventory for Apple devices that cannot reach a patched version and replace or isolate them.

7.87% KEV PoC
  • Apple iOS (iPhone OS) all versions prior to iOS 15.2; Apple also issued emergency fixes for older iOS branches per vendor reporting
  • Apple iPadOS all versions prior to iPadOS 15.2
  • Apple macOS Monterey versions prior to 12.1
  • +7 more
mass≈1 billion+ Apple devices (iOS/iPadOS/macOS/tvOS/watchOS/Safari install base), with practical residual exposure concentrated in legacy iPhones/iPads on old iOS…
CVE-2020-13753
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl.

The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling terminal's input buffer, similar to CVE-2017-5226.

NVD description · AI analysis pending
10.03%
  • webkitgtk webkitgtk
  • webkitgtk wpe webkit
  • webkitgtk fedora
  • +1 more
CVE-2020-11793
A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary

A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash).

NVD description · AI analysis pending
8.83%
  • webkitgtk webkitgtk
  • webkitgtk wpe webkit
  • webkitgtk ubuntu linux
  • +1 more
CVE-2020-10018
WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may

WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed in 2.28.0 with improved memory handling.

NVD description · AI analysis pending
9.85%
  • webkitgtk webkitgtk
  • webkitgtk wpe webkit
  • webkitgtk fedora
  • +1 more
CVE-2019-11070
WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth

WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.

NVD description · AI analysis pending
5.33%
  • webkitgtk webkitgtk
  • webkitgtk wpe webkit
CVE-2019-6251
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections.

WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.

NVD description · AI analysis pending
8.14% PoC
  • gnome epiphany
  • gnome webkitgtk
  • gnome wpe webkit
  • +1 more
CVE-2018-12293
The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to versio

The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer overflow, which could be abused by crafted HTML content.

NVD description · AI analysis pending
8.810%
  • canonical ubuntu linux
  • canonical webkitgtk\+
  • canonical wpe webkit