← Vulnerability feed

Vulnerability record · CVE-2010-1807 · published 10 September 2010

CVE-2010-1807: WebKit floating-point validation flaw allows remote code execution

Apple · Safari

WebKit fails to properly validate floating-point data, specifically handling of a non-standard NaN representation, in Safari 4.x before 4.1.2 and 5.x before 5.0.2, Android before 2.2, and webkitgtk before 1.2.6. A crafted HTML document can trigger memory corruption leading to arbitrary code execution or a crash. Because the flaw sits in a widely deployed rendering engine, any browsing of attacker-controlled content is a risk.

9.3 CVSS 2.0 High EPSS 61% · top 0.9% CWE-20 · Improper input validation
9.3CVSS 2.0 base score
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
44References
16 Jun 2026Last modified by NVD

Description

WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate floating-point data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to non-standard NaN representation.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityRemote code execution in a ubiquitous rendering engine with a 9.3 CVSS score and very high EPSS, though no confirmed in-the-wild exploitation or KEV listing.

What it is

WebKit fails to properly validate floating-point data, specifically handling of a non-standard NaN representation, in Safari 4.x before 4.1.2 and 5.x before 5.0.2, Android before 2.2, and webkitgtk before 1.2.6. A crafted HTML document can trigger memory corruption leading to arbitrary code execution or a crash. Because the flaw sits in a widely deployed rendering engine, any browsing of attacker-controlled content is a risk.

Impact

A remote attacker can execute arbitrary code in the context of the browser or WebKit-based application, or crash it for denial of service. Successful code execution gives the attacker the privileges of the affected process.

Attack surface

Reached over the network by rendering a crafted HTML document in an affected WebKit build; no authentication is required. The CVSS vector shows medium access complexity and no user interaction flag, but in practice the victim must load the malicious page.

Exploitation

Not listed in CISA KEV and no ransomware association is documented. EPSS is high (0.613 probability, 99.1st percentile), and references include a Patch tag plus multiple vendor advisories, indicating public technical detail and fixes rather than confirmed in-the-wild exploitation.

What to do

  • Upgrade to patched versions: Safari 4.1.2/5.0.2 or later, Android 2.2 or later, webkitgtk 1.2.6 or later, and apply the linked vendor errata (Apple, Red Hat, Ubuntu, openSUSE, Mandriva).
  • Retire or isolate end-of-life WebKit-based browsers and embedded webviews that cannot be patched.
  • Restrict browsing of untrusted content and enforce network controls that block known malicious or untrusted sites.
  • Where WebKit is embedded in applications, update the bundled engine to a fixed release and rebuild.
  • Monitor vendor advisories for any further WebKit floating-point handling fixes.

Detection

  • Hunt for crashes or abnormal termination of Safari, Android browser, or webkitgtk processes correlated with visits to untrusted pages.
  • Review proxy and DNS logs for access to sites hosting exploit HTML targeting WebKit NaN handling.
  • Use endpoint detection to flag browser or webview processes spawning unexpected child processes or writing executables after page loads.
  • Track asset inventory for unpatched Safari, Android, and webkitgtk versions against the fixed release thresholds.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html
http://lists.apple.com/archives/security-announce/2010//Sep/msg00001.html Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
http://secunia.com/advisories/41856 Vendor Advisory
http://secunia.com/advisories/42314
http://secunia.com/advisories/43068 Vendor Advisory
http://secunia.com/advisories/43086 Vendor Advisory
http://support.apple.com/kb/HT4333 Vendor Advisory
http://support.apple.com/kb/HT4456
http://trac.webkit.org/changeset/64706
http://www.computerworld.com/s/article/9195058/Researcher_to_release_Web_based_Android_attack
http://www.mandriva.com/security/advisories?name=MDVSA-2011:039
http://www.redhat.com/support/errata/RHSA-2011-0177.html
http://www.securityfocus.com/bid/43047 Patch
http://www.ubuntu.com/usn/USN-1006-1
http://www.vupen.com/english/advisories/2010/2722 Vendor Advisory
http://www.vupen.com/english/advisories/2010/3046 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0212 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0216 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0552 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=627703
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11964
http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html
http://lists.apple.com/archives/security-announce/2010//Sep/msg00001.html Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
http://secunia.com/advisories/41856 Vendor Advisory
http://secunia.com/advisories/42314
http://secunia.com/advisories/43068 Vendor Advisory
http://secunia.com/advisories/43086 Vendor Advisory
http://support.apple.com/kb/HT4333 Vendor Advisory
http://support.apple.com/kb/HT4456
http://trac.webkit.org/changeset/64706
http://www.computerworld.com/s/article/9195058/Researcher_to_release_Web_based_Android_attack
http://www.mandriva.com/security/advisories?name=MDVSA-2011:039
http://www.redhat.com/support/errata/RHSA-2011-0177.html
http://www.securityfocus.com/bid/43047 Patch
http://www.ubuntu.com/usn/USN-1006-1
http://www.vupen.com/english/advisories/2010/2722 Vendor Advisory
http://www.vupen.com/english/advisories/2010/3046 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0212 Vendor Advisory

Track CVE-2010-1807 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed8.8CVE-2026-58704Android Cellular Modem improper authorization allows adjacent privilege escalationAndroid's Cellular Modem component contains a logic error that bypasses permission checks, allowing an attacker within radio/adjacent range to escala…KEVEPSS 0.59%analysed8.8CVE-2025-43529Apple WebKit use-after-free allows code execution via crafted web contentA use-after-free flaw in Apple's WebKit engine was fixed through improved memory management across Safari, iOS, iPadOS, macOS, tvOS, visionOS and wat…KEVEPSS 8.8%analysed8.8CVE-2025-14174Google Chrome ANGLE out-of-bounds memory access on MacChrome on macOS before 143.0.7499.110 contains an out-of-bounds memory access in the ANGLE graphics layer, classified as an out-of-bounds write (CWE-…KEVEPSS 22%analysed8.8CVE-2023-43000Apple WebKit use-after-free via malicious web contentA use-after-free flaw in Apple's WebKit engine was fixed by improved memory management in macOS Ventura 13.5, iOS/iPadOS 16.6, Safari 16.6, and iOS/i…KEVEPSS 3.9%analysed8.8CVE-2025-48543Android use-after-free allows Chrome sandbox escape to system_serverA use-after-free in multiple Android locations lets an attacker escape the Chrome sandbox and reach the Android system_server process. Because the fl…KEVEPSS 0.54%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed

Source: NIST National Vulnerability Database (record CVE-2010-1807), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.