CVE-2012-3748: Apple iPhone OS

Medium severity, CVSS 5.1. EPSS: 16.7% chance of exploitation in the next 30 days.

Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript arrays.

Affected products

  • Apple iPhone OS: up to and including 6.0; version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 1.1.0 only; version 1.1.1 only; …
  • Apple Safari: up to and including 6.0.1; version 1.0 only; version 1.0.0 only; version 1.0.0b1 only; version 1.0.0b2 only; version 1.0.1 only; …

Published 2012-11-03. Last modified 2026-06-16.