PT-2025-51037 · Apple+7 · Safari+14

CVE-2025-43529

·

Published

2025-12-12

·

Updated

2026-09-01

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Safari versions prior to 26.2 iOS versions prior to 18.7.3 iOS versions prior to 26.2 iPadOS versions prior to 18.7.3 iPadOS versions prior to 26.2 macOS Tahoe versions prior to 26.2 tvOS versions prior to 26.2 visionOS versions prior to 26.2 watchOS versions prior to 26.2
Description A use-after-free issue exists in the WebKit rendering engine, which occurs when the software continues to reference memory that has already been freed. This flaw stems from improper memory management within the HTML parsing logic. Processing maliciously crafted web content can lead to memory corruption, allowing a remote attacker to execute arbitrary code and gain full control of the device. There are reports that this issue has been exploited in sophisticated attacks targeting specific individuals on versions of iOS prior to 26.
Recommendations Update Safari to version 26.2. Update iOS to version 18.7.3 or 26.2. Update iPadOS to version 18.7.3 or 26.2. Update macOS Tahoe to version 26.2. Update tvOS to version 26.2. Update visionOS to version 26.2. Update watchOS to version 26.2.

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:23663
ALSA-2025:23700
BDU:2026-00005
CVE-2025-43529
DLA-4414-1
DSA-6083-1
OPENSUSE-SU-2026:20065-1
SUSE-SU-2025:4527-1
SUSE-SU-2025:4528-1
SUSE-SU-2026:0021-1
SUSE-SU-2026:20102-1
USN-7957-1

Affected Products

Almalinux
Centos
Debian
Linuxmint
Apple Macos
Red Hat
Rocky Linux
Safari
Ubuntu
Webkit
Ios
Ipados
Tvos
Visionos
Watchos