CVE-2011-3443: Apple Safari

High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.

Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via vectors related to improper list management for Cascading Style Sheets (CSS) @font-face rules.

Affected products

  • Apple Safari: up to and including 5.0.5; version 1.0 only; version 1.0.0 only; version 1.0.0b1 only; version 1.0.0b2 only; version 1.0.1 only; …

Published 2012-03-02. Last modified 2026-06-16.