Vulnerability intelligence
CVE-2026-43725
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.
CVSS Score
7.1
High
EPSS — Exploit Probability
0.8%
Riskier than 54% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Jul 1, 2026 · latest Jul 1, 2026
Coverage timeline
-
Apple patches 37 WebKit kernel flaws, including sandbox escapeswww.thezdi.com · Jul 1, 2026