← Back to browse · API

CVE-2025-43529

Severity
HIGH
CVSS
8.8
EPSS
0.0877
Risk score
63.27
CISA KEV
Yes
PoC
Yes
Published
2025-12-17
Modified
2026-04-02
First seen
2026-08-07
Aliases
EUVD-2025-203963, GHSA-M9MP-FMFC-G6GC
Products
Apple:Multiple Products, Apple:Safari 0 <26.2, Apple:iOS and iPadOS 0 <18.7.3, Apple:iOS and iPadOS 0 <26.2, Apple:macOS 0 <26.2, Apple:tvOS 0 <26.2, Apple:visionOS 0 <26.2, Apple:watchOS 0 <26.2
Sources
euvd EUVD-2025-203963
cisa.gov CVE-2025-43529
github d5390c69bccbb94ffb67fdff|CVE-2025-43529

Description

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.

References