CVE-2026-43709
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, ma
CVSS
6.5
Medio
EPSS
0.4%
p31
KEV
—
Exploit Today
9
0-100
Publicado: 29 jun 2026 · Última mod.: 27 jul 2026 · CWE-416
0.3%EPSS · 30 días0.4%
2026-08-222026-09-19
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
- support.apple.comhttps://support.apple.com/en-us/127594
- support.apple.comhttps://support.apple.com/en-us/127595
- support.apple.comhttps://support.apple.com/en-us/127685
- support.apple.comhttps://support.apple.com/en-us/128068
- support.apple.comhttps://support.apple.com/en-us/128069
- support.apple.comhttps://support.apple.com/en-us/128070
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-880978.1 ALT12.7%
——4Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.10hCVE-2026-935862.9 BAJ1.7%
——1ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability impact (e.g., a crash of the affected process). The issue is fixed in versions 7.1.2-31 and 6.9.13-56.1dCVE-2026-933828.8 ALT31.2%
——9Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)20hCVE-2026-933749.6 CRÍ29.2%
——9Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)20hCVE-2026-933739.6 CRÍ23.4%
——7Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)20hCVE-2026-924743.3 BAJ4.5%
——1A security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file src/compositor/mpeg4_inline.c of the component Proto Link Handler. The manipulation results in use after free. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. Upgrading to version abi-16.24 mitigates this issue. The patch is identified as e34f4ba349d55cd1849f0bcf4cf46552732e2db7. Upgrading the affected component is recommended.2d