Apple WebKit · CVE-2026-43740

What reproducible evidence looks like.

A public example from our own research. Client reports use the same sequence: observation, evidence, impact, and a specific fix.

Read the technical analysis →
Observation
Case-insensitive backreference matching in WebKit's YARR JIT could index beyond a 256-entry canonicalisation table.
Evidence
A captured character above U+00FF drove an out-of-bounds read and a match/no-match oracle.
Impact
Crafted web content could disclose WebKit process memory.
Fix
The patch adds the missing bounds check before the table lookup. Apple shipped the fix in the 26.5.2 updates.
Engagement shape

Nothing exotic. The shape that lets the work be useful.

A scoping call to understand what you're protecting and what you're worried about. Testing. A written report with reproducible evidence and prioritised fixes.

Most engagements take two to four weeks. We can run them as a one-off or as a recurring programme — if you want the latter, see the annual programme.

Scope first

A short note is enough. We reply within one Australian business day.

Send the scope and timing.

Tell us what needs testing, the environment involved, and any deadline. We will respond with the questions needed to define the work.