Vulnerability record · CVE-2010-1807 · published 10 September 2010
CVE-2010-1807: WebKit floating-point validation flaw allows remote code execution
Apple · Safari
WebKit fails to properly validate floating-point data, specifically handling of a non-standard NaN representation, in Safari 4.x before 4.1.2 and 5.x before 5.0.2, Android before 2.2, and webkitgtk before 1.2.6. A crafted HTML document can trigger memory corruption leading to arbitrary code execution or a crash. Because the flaw sits in a widely deployed rendering engine, any browsing of attacker-controlled content is a risk.
Description
WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate floating-point data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to non-standard NaN representation.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution in a ubiquitous rendering engine with a 9.3 CVSS score and very high EPSS, though no confirmed in-the-wild exploitation or KEV listing.
What it is
WebKit fails to properly validate floating-point data, specifically handling of a non-standard NaN representation, in Safari 4.x before 4.1.2 and 5.x before 5.0.2, Android before 2.2, and webkitgtk before 1.2.6. A crafted HTML document can trigger memory corruption leading to arbitrary code execution or a crash. Because the flaw sits in a widely deployed rendering engine, any browsing of attacker-controlled content is a risk.
Impact
A remote attacker can execute arbitrary code in the context of the browser or WebKit-based application, or crash it for denial of service. Successful code execution gives the attacker the privileges of the affected process.
Attack surface
Reached over the network by rendering a crafted HTML document in an affected WebKit build; no authentication is required. The CVSS vector shows medium access complexity and no user interaction flag, but in practice the victim must load the malicious page.
Exploitation
Not listed in CISA KEV and no ransomware association is documented. EPSS is high (0.613 probability, 99.1st percentile), and references include a Patch tag plus multiple vendor advisories, indicating public technical detail and fixes rather than confirmed in-the-wild exploitation.
What to do
- Upgrade to patched versions: Safari 4.1.2/5.0.2 or later, Android 2.2 or later, webkitgtk 1.2.6 or later, and apply the linked vendor errata (Apple, Red Hat, Ubuntu, openSUSE, Mandriva).
- Retire or isolate end-of-life WebKit-based browsers and embedded webviews that cannot be patched.
- Restrict browsing of untrusted content and enforce network controls that block known malicious or untrusted sites.
- Where WebKit is embedded in applications, update the bundled engine to a fixed release and rebuild.
- Monitor vendor advisories for any further WebKit floating-point handling fixes.
Detection
- Hunt for crashes or abnormal termination of Safari, Android browser, or webkitgtk processes correlated with visits to untrusted pages.
- Review proxy and DNS logs for access to sites hosting exploit HTML targeting WebKit NaN handling.
- Use endpoint detection to flag browser or webview processes spawning unexpected child processes or writing executables after page loads.
- Track asset inventory for unpatched Safari, Android, and webkitgtk versions against the fixed release thresholds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-1807 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-1807), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.