CVE-2026-43731
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10,
CVSS
8.8
High
EPSS
0.4%
p35
KEV
—
Exploit Today
10
0-100
Published: Jun 29, 2026 · Last modified: Aug 17, 2026 · CWE-416
0.4%EPSS · 30 days0.4%
2026-08-252026-09-23
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
- support.apple.comhttps://support.apple.com/en-us/127594
- support.apple.comhttps://support.apple.com/en-us/127595
- support.apple.comhttps://support.apple.com/en-us/127685
- support.apple.comhttps://support.apple.com/en-us/128068
- support.apple.comhttps://support.apple.com/en-us/128069
- support.apple.comhttps://support.apple.com/en-us/128070
- support.apple.comhttps://support.apple.com/en-us/148287
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-918187.8 HIG6.8%
——2A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently accessed, resulting in an application crash.5hCVE-2026-918167.8 HIG6.8%
——2A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access an annotation object after it has been released, resulting in a use-after-free condition and application crash.5hCVE-2026-918097.8 HIG6.8%
——2A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting in an application crash.5hCVE-2026-918067.8 HIG6.8%
——2A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF form fields. Embedded JavaScript may access form-field references after the corresponding fields have been released, resulting in an application crash.5hCVE-2026-918057.8 HIG6.8%
——2A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s PDF page-tree handling. A specially crafted PDF can trigger page-structure changes during rendering, causing the application to access released page objects and resulting in memory corruption and an application crash.5hCVE-2026-917997.8 HIG8.4%
——3A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects. A specially crafted PDF may cause the application to access a released object during array processing, potentially resulting in application crashes or arbitrary code execution.5h