A use after free issue exists in WebKit's handling of elements with run-in styling. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved handling of object pointers. Credit to wushi of team509, working with TippingPoint's Zero Day Initiative for reporting this issue. References: https://bugs.webkit.org/show_bug.cgi?id=41375 http://trac.webkit.org/changeset/63772
This is now public: http://support.apple.com/kb/HT4333