CVE-2026-43721
published 2026-06-29CVE-2026-43721: This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.44%
36.5th percentile
This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to silently hijack clipboard data.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 26.5.2 | 26.5.2 |
| apple | ipados | < 26.5.2 | 26.5.2 |
| apple | iphone_os | < 26.5.2 | 26.5.2 |
| apple | macos | < 26.5.2 | 26.5.2 |
| apple | macos | >= 26.0 < 26.5.2 | 26.5.2 |
| apple | safari | < 26.5.2 | 26.5.2 |
| apple | tvos | < 26.6 | 26.6 |
| apple | visionos | < 26.6 | 26.6 |
| apple | watchos | < 26.6 | 26.6 |
| webkitgtk | webkitgtk | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data
vendor_redhat·2026-07-10·CVSS 6.5
CVE-2026-43721 [MEDIUM] CWE-732 webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data
webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data
This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may be able to silently hijack clipboard data.
A flaw was found in WebKitGTK. A malicious website can silently hijack clipboard data due to improper state management.
Package: pywebkitgtk (Red Hat Enterprise Linux 6) - Out of support scope
Package: webkitgtk (Red Hat Enterprise Linux 6) - Out of support scope
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Out of support scope
Package: webkitgtk4 (Red Hat Enterprise Linux 7) - Out of support scope
Package: webkit2gtk3 (Red Hat Enterprise Linux 8) - Affected
Package: webkit2gtk3 (Red Hat E
VulDB
Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Website Remote Code Execution
vuldb·2026-06-30
CVE-2026-43721 [CRITICAL] Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Website Remote Code Execution
A vulnerability was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. It has been rated as critical. This affects an unknown function of the component Website Handler. Performing a manipulation results in Remote Code Execution.
This vulnerability is known as CVE-2026-43721. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
GHSA
This issue was addressed through improved state management.
ghsa_unreviewed·2026-06-29
CVE-2026-43721 [HIGH] CWE-732 This issue was addressed through improved state management.
This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may be able to silently hijack clipboard data.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-43721 webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data [epel-all]
bugzilla·2026-08-31·CVSS 6.5
CVE-2026-43721 [MEDIUM] CVE-2026-43721 webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data [epel-all]
CVE-2026-43721 webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
This issue was addressed through improved state management.
Impact: a malicious website may silently hijack clipboard data
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html
WebKit Bug: https://bugs.webkit.org/show_bug.cgi?id=313478
Bugzilla
CVE-2026-43721 webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data [fedora-all]
bugzilla·2026-08-31·CVSS 6.5
CVE-2026-43721 [MEDIUM] CVE-2026-43721 webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data [fedora-all]
CVE-2026-43721 webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
This issue was addressed through improved state management.
Impact: a malicious website may silently hijack clipboard data
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html
WebKit Bug: https://bugs.webkit.org/show_bug.cgi?id=313478
Bugzilla
CVE-2026-43721 webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data
bugzilla·2026-07-14·CVSS 6.5
CVE-2026-43721 [MEDIUM] CVE-2026-43721 webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data
CVE-2026-43721 webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data
This issue was addressed through improved state management.
Impact: a malicious website may silently hijack clipboard data
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html
WebKit Bug: https://bugs.webkit.org/show_bug.cgi?id=313478
Sans Isc
Apple Patches Everything (July 2026), (Wed, Jul 29th)
blogs_sans_isc·2026-07-29·CVSS 5.5
CVE-2026-28849 [MEDIUM] Apple Patches Everything (July 2026), (Wed, Jul 29th)
Apple Patches Everything (July 2026)
Published: 2026-07-29. Last Updated: 2026-07-29 07:32:37 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions (14 and 15), while other operating system patches only covered the current 26 versions.
A total of 187 vulnerabilities are addressed in this update. Many cover multiple operating systems. Apple did not label any of the vulnerabilities as already being exploited.
Three vulnerabilities that caught my interest are CVE-2026-28849, CVE-2026-28900, and CVE-2026-28914. These issues appear to be the vulnerability described in https://m
Sans Isc
June 2026 Apple Updates, (Tue, Jun 30th)
blogs_sans_isc·2026-06-30·CVSS 9.1
CVE-2026-39868 [CRITICAL] June 2026 Apple Updates, (Tue, Jun 30th)
June 2026 Apple Updates
Published: 2026-06-30. Last Updated: 2026-06-30 09:31:27 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
Apple released updates for iOS/iPadOS, macOS, and Safari on Monday. There have been no updates for other Apple operating systems (visionOS, watchOS, tvOS). Usually, Apple updates all products at the same time.
Most of the vulnerabilities affect the web browser (WebKit, libxslt, WebRTC, and Web Extension). Only four of the vulnerabilities are not directly related to web content: Three Kernel issues and one vulnerability in the IOGPUFamily.
None of the vulnerabilities is labeled as "exploited".
iOS 26.5.2 and iPadOS 26.5.2 macOS Tahoe 26.5.2 Safari 26.5.2
CVE-2026-39868: An app may be able to cause unexpected system termination or corrupt kernel memory.
A
2026-06-29
Published