Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

The issue was addressed with improved memory handling. (CVE-2026-43658)

0
High
Published: 05/11/2026 (05/11/2026, 21:31:40 UTC)
Source: GCVE Database

Description

CVE-2026-43658 is a high-severity vulnerability in WebKitGTK that causes an unexpected process crash when processing maliciously crafted web content due to improper memory handling. The issue has been addressed with improved memory handling and fixed in iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5, and relevant WebKitGTK packages. Exploitation requires tricking a user into loading malicious content, potentially leading to denial of service. While remote code execution is not confirmed, it cannot be ruled out. Red Hat provides updates and advises mitigation by avoiding untrusted web content or removing affected packages where feasible.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/18/2026, 00:56:20 UTC

Technical Analysis

CVE-2026-43658 is a vulnerability in WebKitGTK involving improper memory handling that can cause an unexpected process crash when processing maliciously crafted web content. The flaw relates to buffer overflow issues (CWE-119, CWE-120). Exploitation requires user interaction to load malicious content, potentially leading to denial of service and possibly remote code execution, though the latter is not confirmed. Red Hat's advisory highlights that the vulnerability affects packages that use WebKitGTK4, such as GNOME components, and can be exploited locally or via the network in some cases. Mitigations include avoiding untrusted content and removing or updating affected packages. The issue is fixed in updated WebKitGTK packages and Apple OS versions 26.5.

Potential Impact

The vulnerability can cause an unexpected crash of the WebKitGTK process, leading to denial of service. Confidentiality impact is rated high due to potential unauthorized code execution, though this is not confirmed. The flaw could allow attackers to disrupt applications that rely on WebKitGTK to process web content, especially graphical applications in GNOME environments. Remote exploitation requires user interaction except in some GNOME shell cases where local network attackers may exploit it without user interaction.

Mitigation Recommendations

A fix is available in updated versions of WebKitGTK and Apple OS releases 26.5. Users should apply these official patches promptly. Red Hat advises avoiding processing or loading untrusted web content with WebKitGTK. Where feasible, consider removing packages that depend on WebKitGTK4 to reduce exposure, noting that removal may impact GNOME functionality. WebKitGTK3 can be removed without consequence. No additional vendor advisories indicate that no action is required; thus, patching and cautious content handling are recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-gc3p-ph3x-xqq6
Osv Schema Version
1.4.0
Aliases
["CVE-2026-43658"]
Ecosystems
[]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6a83aa87bf8831d539e33f12

Added to database: 08/18/2026, 00:42:47 UTC

Last enriched: 08/18/2026, 00:56:20 UTC

Last updated: 08/18/2026, 01:18:56 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses