Buffer overflow in WebKitGTK+ and WPE WebKit - CVE-2025-46298
Published: January 12, 2026 / Updated: February 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to a boundary error when processing HTML content in WebKit. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and perform a denial of service attack.
Affected software
WPE WebKit
macOS
iPadOS
Apple iOS
tvOS
visionOS
watchOS
Apple Safari
How to mitigate CVE-2025-46298
Apple Safari - update to 26.2
iPadOS - update to 26.2 23C55
Apple iOS - update to 26.2 23C55
tvOS - update to 26.2 23K54
visionOS - update to 26.2
watchOS - update to 26.2 23S303
External References
Related Security Bulletins
- Two vulnerabilities in WebKitGTK+ and WPE WebKit
- Multiple vulnerabilities in Apple macOS Tahoe
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Safari
- Multiple vulnerabilities in Apple visionOS
- Multiple vulnerabilities in Apple iOS 26 and iPadOS 26
- Multiple vulnerabilities in Apple watchOS