CVE-2026-43804

Public on 2026-07-27
Modified on 2026-08-21
Description
This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. Visiting a website may lead to an app denial-of-service.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
6.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core gtk2 Not Affected
Amazon Linux 2 - Core gtk3 Not Affected
Amazon Linux 2023 gtk3 Not Affected
Amazon Linux 2027 Preview gtk3 Not Affected
Amazon Linux 2023 gtk4 Not Affected
Amazon Linux 2027 Preview gtk4 Not Affected
Amazon Linux 2 - Core webkitgtk3 No Fix Planned
Amazon Linux 2 - Core webkitgtk4 2026-08-31 ALAS2-2026-3891 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H