iOS Exploit for Sale (CVE-2025-43529, CVE-2026-20700, CVE-2025-14174)
Dark Web2026-09-14, 10:39
For informational purposes only.
Vulnerable versions: Apple iOS 15.0–18.2
Price: $10k (3 hands max), $18k (1 hand only)
According to the author’s description, the exploit relies on well-known CVEs and a web trigger via the Safari browser. This implies a scenario in which the vulnerability can be triggered after opening a specially crafted webpage in Safari.
CVE-2025-43529 - a use-after-free vulnerability in WebKit, where a specially crafted web page could lead to the execution of arbitrary code.
CVE-2025-14174 - another WebKit vulnerability related to a memory corruption when processing malicious web content.
CVE-2026-20700 — a memory corruption vulnerability in the dyld component that, when combined with an existing write-to-memory capability, could allow arbitrary code execution.
iOS remains the second-largest mobile OS in the world: according to StatCounter, as of May 2026, its share of the mobile operating system market was 31,95% globally.
Vulnerabilities
Vendors
Products