PT-2025-51037 · Apple+7 · Safari+14
CVE-2025-43529
·
Published
2025-12-12
·
Updated
2026-09-01
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Safari versions prior to 26.2
iOS versions prior to 18.7.3
iOS versions prior to 26.2
iPadOS versions prior to 18.7.3
iPadOS versions prior to 26.2
macOS Tahoe versions prior to 26.2
tvOS versions prior to 26.2
visionOS versions prior to 26.2
watchOS versions prior to 26.2
Description
A use-after-free issue exists in the WebKit rendering engine, which occurs when the software continues to reference memory that has already been freed. This flaw stems from improper memory management within the HTML parsing logic. Processing maliciously crafted web content can lead to memory corruption, allowing a remote attacker to execute arbitrary code and gain full control of the device. There are reports that this issue has been exploited in sophisticated attacks targeting specific individuals on versions of iOS prior to 26.
Recommendations
Update Safari to version 26.2.
Update iOS to version 18.7.3 or 26.2.
Update iPadOS to version 18.7.3 or 26.2.
Update macOS Tahoe to version 26.2.
Update tvOS to version 26.2.
Update visionOS to version 26.2.
Update watchOS to version 26.2.
Fix
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Centos
Debian
Linuxmint
Apple Macos
Red Hat
Rocky Linux
Safari
Ubuntu
Webkit
Ios
Ipados
Tvos
Visionos
Watchos