Apple Multiple Products Use-After-Free WebKit Vulnerability
cve CVE-2025-43529 3 sources, 3 claims · Watch
CISA Known Exploited Vulnerabilities writes:
Apple Multiple Products Use-After-Free WebKit Vulnerability Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://support.apple.com/e… the claim
Apple Multiple Products Use-After-Free WebKit Vulnerability Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://support.apple.com/e… the claim
What it is to other things
| affects | apple/ipados NVD |
| affects | apple/iphone_os NVD |
| affects | apple/macos NVD |
| affects | apple/safari NVD |
| affects | apple/tvos NVD |
| affects | apple/visionos NVD |
| affects | apple/watchos NVD |
| made_by | apple NVD |
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Cvss cvss | NVD | 8.8receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Safari",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "iOS and iPadOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "18.7.3",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "macOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "tvOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "visionOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "watchOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"source": "product-security@apple.com"
}
],
"cisaActionDue": "2026-01-05",
"cisaExploitAdd": "2025-12-15",
"cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"cisaVulnerabilityName": "Apple Multiple Products Use-After-Free WebKit Vulnerability",
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3ECBF838-536C-47F9-9876-C526B8ED32EC",
"versionEndExcluding": "26.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6547722A-1226-4E23-B3AE-8692B07C2657",
"versionEndExcluding": "18.7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8B71D919-1AA2-4F17-A834-4B703E36F7E2",
"versionEndExcluding": "26.2",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8928A377-93BD-49AD-B4FE-5B2328EBDB70",
"versionEndExcluding": "18.7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "10FD01C3-D77F-4FE4-8195-F2C59FB1321C",
"versionEndExcluding": "26.2",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "825BB848-93B2-4A3E-86D8-16CB37DF9302",
"versionEndExcluding": "26.2",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E0BBFB45-21F3-4B72-8DB1-BE72AFE0D2AB",
"versionEndExcluding": "26.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "EB10D901-4800-4DF9-AB35-48017C178161",
"versionEndExcluding": "26.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "15574823-ECE0-4394-99BC-6AFA34E599CC",
"versionEndExcluding": "26.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report."
},
{
"lang": "es",
"value": "Un problema de uso después de liberación se abordó con una gestión de memoria mejorada. Este problema está solucionado en watchOS 26.2, Safari 26.2, iOS 18.7.3 y iPadOS 18.7.3, iOS 26.2 y iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, tvOS 26.2. El procesamiento de contenido web creado con fines maliciosos puede conducir a la ejecución de código arbitrario. Apple tiene conocimiento de un informe que indica que este problema pudo haber sido explotado en un ataque extremadamente sofisticado contra individuos específicos y dirigidos en versiones de iOS anteriores a iOS 26. También se emitió CVE-2025-14174 en respuesta a este informe."
}
],
"id": "CVE-2025-43529",
"lastModified": "2026-09-30T20:10:00.247",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-43529",
"options": [
{
"exploitation": "active"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-18T04:55:16.426232Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-17T21:16:11.570",
"references": [
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125884"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125885"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125886"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125889"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125890"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125891"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125892"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"tags": [
"US Government Resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-43529"
}
],
"sourceIdentifier": "product-security@apple.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-416"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
| Cvss cvss | Red Hat | 8.8receipt
What the source handed over{
"CVE": "CVE-2025-43529",
"CWE": "CWE-825",
"advisories": [
"RHSA-2025:23975",
"RHSA-2025:23700",
"RHSA-2025:23974",
"RHSA-2025:23663",
"RHSA-2025:23971",
"RHSA-2025:23970",
"RHSA-2025:23973",
"RHSA-2025:23972",
"RHSA-2025:23968",
"RHSA-2025:23967",
"RHSA-2025:23969"
],
"affected_packages": [
"webkit2gtk3-0:2.50.4-1.el8_4",
"webkit2gtk3-0:2.50.4-1.el9_4",
"webkit2gtk3-0:2.50.4-1.el8_2",
"webkit2gtk3-0:2.50.4-1.el9_2",
"webkit2gtk3-0:2.50.4-1.el8_8",
"webkit2gtk3-0:2.50.4-1.el9_7",
"webkit2gtk3-0:2.50.4-1.el8_6",
"webkit2gtk3-0:2.50.4-1.el9_6",
"webkitgtk4-0:2.50.4-2.el7_9",
"webkit2gtk3-0:2.50.4-1.el9_0",
"webkit2gtk3-0:2.50.4-1.el8_10"
],
"bugzilla": "2423166",
"bugzilla_description": "webkitgtk: webkitgtk: Use-after-free due to improper memory management",
"cvss3_score": "8.8",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-12-16T00:00:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-43529.json",
"severity": "important"
} | — |
| Cwe cwe | Red Hat | CWE-825receipt
What the source handed over{
"CVE": "CVE-2025-43529",
"CWE": "CWE-825",
"advisories": [
"RHSA-2025:23975",
"RHSA-2025:23700",
"RHSA-2025:23974",
"RHSA-2025:23663",
"RHSA-2025:23971",
"RHSA-2025:23970",
"RHSA-2025:23973",
"RHSA-2025:23972",
"RHSA-2025:23968",
"RHSA-2025:23967",
"RHSA-2025:23969"
],
"affected_packages": [
"webkit2gtk3-0:2.50.4-1.el8_4",
"webkit2gtk3-0:2.50.4-1.el9_4",
"webkit2gtk3-0:2.50.4-1.el8_2",
"webkit2gtk3-0:2.50.4-1.el9_2",
"webkit2gtk3-0:2.50.4-1.el8_8",
"webkit2gtk3-0:2.50.4-1.el9_7",
"webkit2gtk3-0:2.50.4-1.el8_6",
"webkit2gtk3-0:2.50.4-1.el9_6",
"webkitgtk4-0:2.50.4-2.el7_9",
"webkit2gtk3-0:2.50.4-1.el9_0",
"webkit2gtk3-0:2.50.4-1.el8_10"
],
"bugzilla": "2423166",
"bugzilla_description": "webkitgtk: webkitgtk: Use-after-free due to improper memory management",
"cvss3_score": "8.8",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-12-16T00:00:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-43529.json",
"severity": "important"
} | — |
| Cwes cwes | CISA Known Exploited Vulnerabilities | CWE-416receipt
What the source handed over{
"cveID": "CVE-2025-43529",
"cwes": "CWE-416",
"dateAdded": "2025-12-15",
"dueDate": "2026-01-05",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://support.apple.com/en-us/125884 ; https://support.apple.com/en-us/125892 ; https://support.apple.com/en-us/125885 ; https://support.apple.com/en-us/125886 ; https://support.apple.com/en-us/125889 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43529",
"product": "Multiple Products",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.",
"vendorProject": "Apple",
"vulnerabilityName": "Apple Multiple Products Use-After-Free WebKit Vulnerability"
} | — |
| Due date due_date | CISA Known Exploited Vulnerabilities | 2026-01-05receipt
What the source handed over{
"cveID": "CVE-2025-43529",
"cwes": "CWE-416",
"dateAdded": "2025-12-15",
"dueDate": "2026-01-05",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://support.apple.com/en-us/125884 ; https://support.apple.com/en-us/125892 ; https://support.apple.com/en-us/125885 ; https://support.apple.com/en-us/125886 ; https://support.apple.com/en-us/125889 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43529",
"product": "Multiple Products",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.",
"vendorProject": "Apple",
"vulnerabilityName": "Apple Multiple Products Use-After-Free WebKit Vulnerability"
} | — |
| Exploited exploited | CISA Known Exploited Vulnerabilities | yesreceipt
What the source handed over{
"cveID": "CVE-2025-43529",
"cwes": "CWE-416",
"dateAdded": "2025-12-15",
"dueDate": "2026-01-05",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://support.apple.com/en-us/125884 ; https://support.apple.com/en-us/125892 ; https://support.apple.com/en-us/125885 ; https://support.apple.com/en-us/125886 ; https://support.apple.com/en-us/125889 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43529",
"product": "Multiple Products",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.",
"vendorProject": "Apple",
"vulnerabilityName": "Apple Multiple Products Use-After-Free WebKit Vulnerability"
} | — |
| Forensic triage forensic_triage | CISA Known Exploited Vulnerabilities | falsereceipt
What the source handed over{
"cveID": "CVE-2025-43529",
"cwes": "CWE-416",
"dateAdded": "2025-12-15",
"dueDate": "2026-01-05",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://support.apple.com/en-us/125884 ; https://support.apple.com/en-us/125892 ; https://support.apple.com/en-us/125885 ; https://support.apple.com/en-us/125886 ; https://support.apple.com/en-us/125889 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43529",
"product": "Multiple Products",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.",
"vendorProject": "Apple",
"vulnerabilityName": "Apple Multiple Products Use-After-Free WebKit Vulnerability"
} | — |
| Known ransomware campaign use known_ransomware_campaign_use | CISA Known Exploited Vulnerabilities | Unknownreceipt
What the source handed over{
"cveID": "CVE-2025-43529",
"cwes": "CWE-416",
"dateAdded": "2025-12-15",
"dueDate": "2026-01-05",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://support.apple.com/en-us/125884 ; https://support.apple.com/en-us/125892 ; https://support.apple.com/en-us/125885 ; https://support.apple.com/en-us/125886 ; https://support.apple.com/en-us/125889 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43529",
"product": "Multiple Products",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.",
"vendorProject": "Apple",
"vulnerabilityName": "Apple Multiple Products Use-After-Free WebKit Vulnerability"
} | — |
| Packages packages | Red Hat | webkit2gtk3-0:2.50.4-1.el8_4, webkit2gtk3-0:2.50.4-1.el9_4, webkit2gtk3-0:2.50.4-1.el8_2, webkit2gtk3-0:2.50.4-1.el9_2, webkit2gtk3-0:2.50.4-1.el8_8, webkit2gtk3-0:2.50.4-1.el9_7, webkit2gtk3-0:2.50.4-1.el8_6, webkit2gtk3-0:2.50.4-1.el9_6, webkitgtk4-0:2.50.4-2.el7_9, webkit2gtk3-0:2.50.4-1.el9_0, webkit2gtk3-0:2.50.4-1.el8_10receipt
What the source handed over{
"CVE": "CVE-2025-43529",
"CWE": "CWE-825",
"advisories": [
"RHSA-2025:23975",
"RHSA-2025:23700",
"RHSA-2025:23974",
"RHSA-2025:23663",
"RHSA-2025:23971",
"RHSA-2025:23970",
"RHSA-2025:23973",
"RHSA-2025:23972",
"RHSA-2025:23968",
"RHSA-2025:23967",
"RHSA-2025:23969"
],
"affected_packages": [
"webkit2gtk3-0:2.50.4-1.el8_4",
"webkit2gtk3-0:2.50.4-1.el9_4",
"webkit2gtk3-0:2.50.4-1.el8_2",
"webkit2gtk3-0:2.50.4-1.el9_2",
"webkit2gtk3-0:2.50.4-1.el8_8",
"webkit2gtk3-0:2.50.4-1.el9_7",
"webkit2gtk3-0:2.50.4-1.el8_6",
"webkit2gtk3-0:2.50.4-1.el9_6",
"webkitgtk4-0:2.50.4-2.el7_9",
"webkit2gtk3-0:2.50.4-1.el9_0",
"webkit2gtk3-0:2.50.4-1.el8_10"
],
"bugzilla": "2423166",
"bugzilla_description": "webkitgtk: webkitgtk: Use-after-free due to improper memory management",
"cvss3_score": "8.8",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-12-16T00:00:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-43529.json",
"severity": "important"
} | — |
| Product product not compared | CISA Known Exploited Vulnerabilities | Multiple Productsreceipt
What the source handed over{
"cveID": "CVE-2025-43529",
"cwes": "CWE-416",
"dateAdded": "2025-12-15",
"dueDate": "2026-01-05",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://support.apple.com/en-us/125884 ; https://support.apple.com/en-us/125892 ; https://support.apple.com/en-us/125885 ; https://support.apple.com/en-us/125886 ; https://support.apple.com/en-us/125889 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43529",
"product": "Multiple Products",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.",
"vendorProject": "Apple",
"vulnerabilityName": "Apple Multiple Products Use-After-Free WebKit Vulnerability"
} | — |
| Product product not compared | NVD | Safarireceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Safari",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "iOS and iPadOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "18.7.3",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "macOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "tvOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "visionOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "watchOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"source": "product-security@apple.com"
}
],
"cisaActionDue": "2026-01-05",
"cisaExploitAdd": "2025-12-15",
"cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"cisaVulnerabilityName": "Apple Multiple Products Use-After-Free WebKit Vulnerability",
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3ECBF838-536C-47F9-9876-C526B8ED32EC",
"versionEndExcluding": "26.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6547722A-1226-4E23-B3AE-8692B07C2657",
"versionEndExcluding": "18.7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8B71D919-1AA2-4F17-A834-4B703E36F7E2",
"versionEndExcluding": "26.2",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8928A377-93BD-49AD-B4FE-5B2328EBDB70",
"versionEndExcluding": "18.7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "10FD01C3-D77F-4FE4-8195-F2C59FB1321C",
"versionEndExcluding": "26.2",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "825BB848-93B2-4A3E-86D8-16CB37DF9302",
"versionEndExcluding": "26.2",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E0BBFB45-21F3-4B72-8DB1-BE72AFE0D2AB",
"versionEndExcluding": "26.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "EB10D901-4800-4DF9-AB35-48017C178161",
"versionEndExcluding": "26.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "15574823-ECE0-4394-99BC-6AFA34E599CC",
"versionEndExcluding": "26.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report."
},
{
"lang": "es",
"value": "Un problema de uso después de liberación se abordó con una gestión de memoria mejorada. Este problema está solucionado en watchOS 26.2, Safari 26.2, iOS 18.7.3 y iPadOS 18.7.3, iOS 26.2 y iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, tvOS 26.2. El procesamiento de contenido web creado con fines maliciosos puede conducir a la ejecución de código arbitrario. Apple tiene conocimiento de un informe que indica que este problema pudo haber sido explotado en un ataque extremadamente sofisticado contra individuos específicos y dirigidos en versiones de iOS anteriores a iOS 26. También se emitió CVE-2025-14174 en respuesta a este informe."
}
],
"id": "CVE-2025-43529",
"lastModified": "2026-09-30T20:10:00.247",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-43529",
"options": [
{
"exploitation": "active"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-18T04:55:16.426232Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-17T21:16:11.570",
"references": [
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125884"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125885"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125886"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125889"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125890"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125891"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125892"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"tags": [
"US Government Resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-43529"
}
],
"sourceIdentifier": "product-security@apple.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-416"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
| Severity severity | Red Hat | important A flaw that can easily compromise confidentiality, integrity or availability. receipt
What the source handed over{
"CVE": "CVE-2025-43529",
"CWE": "CWE-825",
"advisories": [
"RHSA-2025:23975",
"RHSA-2025:23700",
"RHSA-2025:23974",
"RHSA-2025:23663",
"RHSA-2025:23971",
"RHSA-2025:23970",
"RHSA-2025:23973",
"RHSA-2025:23972",
"RHSA-2025:23968",
"RHSA-2025:23967",
"RHSA-2025:23969"
],
"affected_packages": [
"webkit2gtk3-0:2.50.4-1.el8_4",
"webkit2gtk3-0:2.50.4-1.el9_4",
"webkit2gtk3-0:2.50.4-1.el8_2",
"webkit2gtk3-0:2.50.4-1.el9_2",
"webkit2gtk3-0:2.50.4-1.el8_8",
"webkit2gtk3-0:2.50.4-1.el9_7",
"webkit2gtk3-0:2.50.4-1.el8_6",
"webkit2gtk3-0:2.50.4-1.el9_6",
"webkitgtk4-0:2.50.4-2.el7_9",
"webkit2gtk3-0:2.50.4-1.el9_0",
"webkit2gtk3-0:2.50.4-1.el8_10"
],
"bugzilla": "2423166",
"bugzilla_description": "webkitgtk: webkitgtk: Use-after-free due to improper memory management",
"cvss3_score": "8.8",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-12-16T00:00:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-43529.json",
"severity": "important"
} | high |
| Status status | NVD | Analyzedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Safari",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "iOS and iPadOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "18.7.3",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "macOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "tvOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "visionOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "watchOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"source": "product-security@apple.com"
}
],
"cisaActionDue": "2026-01-05",
"cisaExploitAdd": "2025-12-15",
"cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"cisaVulnerabilityName": "Apple Multiple Products Use-After-Free WebKit Vulnerability",
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3ECBF838-536C-47F9-9876-C526B8ED32EC",
"versionEndExcluding": "26.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6547722A-1226-4E23-B3AE-8692B07C2657",
"versionEndExcluding": "18.7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8B71D919-1AA2-4F17-A834-4B703E36F7E2",
"versionEndExcluding": "26.2",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8928A377-93BD-49AD-B4FE-5B2328EBDB70",
"versionEndExcluding": "18.7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "10FD01C3-D77F-4FE4-8195-F2C59FB1321C",
"versionEndExcluding": "26.2",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "825BB848-93B2-4A3E-86D8-16CB37DF9302",
"versionEndExcluding": "26.2",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E0BBFB45-21F3-4B72-8DB1-BE72AFE0D2AB",
"versionEndExcluding": "26.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "EB10D901-4800-4DF9-AB35-48017C178161",
"versionEndExcluding": "26.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "15574823-ECE0-4394-99BC-6AFA34E599CC",
"versionEndExcluding": "26.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report."
},
{
"lang": "es",
"value": "Un problema de uso después de liberación se abordó con una gestión de memoria mejorada. Este problema está solucionado en watchOS 26.2, Safari 26.2, iOS 18.7.3 y iPadOS 18.7.3, iOS 26.2 y iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, tvOS 26.2. El procesamiento de contenido web creado con fines maliciosos puede conducir a la ejecución de código arbitrario. Apple tiene conocimiento de un informe que indica que este problema pudo haber sido explotado en un ataque extremadamente sofisticado contra individuos específicos y dirigidos en versiones de iOS anteriores a iOS 26. También se emitió CVE-2025-14174 en respuesta a este informe."
}
],
"id": "CVE-2025-43529",
"lastModified": "2026-09-30T20:10:00.247",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-43529",
"options": [
{
"exploitation": "active"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-18T04:55:16.426232Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-17T21:16:11.570",
"references": [
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125884"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125885"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125886"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125889"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125890"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125891"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125892"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"tags": [
"US Government Resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-43529"
}
],
"sourceIdentifier": "product-security@apple.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-416"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
| Vendor vendor | NVD | Applereceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Safari",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "iOS and iPadOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "18.7.3",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "macOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "tvOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "visionOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "watchOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"source": "product-security@apple.com"
}
],
"cisaActionDue": "2026-01-05",
"cisaExploitAdd": "2025-12-15",
"cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"cisaVulnerabilityName": "Apple Multiple Products Use-After-Free WebKit Vulnerability",
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3ECBF838-536C-47F9-9876-C526B8ED32EC",
"versionEndExcluding": "26.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6547722A-1226-4E23-B3AE-8692B07C2657",
"versionEndExcluding": "18.7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8B71D919-1AA2-4F17-A834-4B703E36F7E2",
"versionEndExcluding": "26.2",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8928A377-93BD-49AD-B4FE-5B2328EBDB70",
"versionEndExcluding": "18.7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "10FD01C3-D77F-4FE4-8195-F2C59FB1321C",
"versionEndExcluding": "26.2",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "825BB848-93B2-4A3E-86D8-16CB37DF9302",
"versionEndExcluding": "26.2",
"versionStartIncluding": "26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E0BBFB45-21F3-4B72-8DB1-BE72AFE0D2AB",
"versionEndExcluding": "26.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "EB10D901-4800-4DF9-AB35-48017C178161",
"versionEndExcluding": "26.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "15574823-ECE0-4394-99BC-6AFA34E599CC",
"versionEndExcluding": "26.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report."
},
{
"lang": "es",
"value": "Un problema de uso después de liberación se abordó con una gestión de memoria mejorada. Este problema está solucionado en watchOS 26.2, Safari 26.2, iOS 18.7.3 y iPadOS 18.7.3, iOS 26.2 y iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, tvOS 26.2. El procesamiento de contenido web creado con fines maliciosos puede conducir a la ejecución de código arbitrario. Apple tiene conocimiento de un informe que indica que este problema pudo haber sido explotado en un ataque extremadamente sofisticado contra individuos específicos y dirigidos en versiones de iOS anteriores a iOS 26. También se emitió CVE-2025-14174 en respuesta a este informe."
}
],
"id": "CVE-2025-43529",
"lastModified": "2026-09-30T20:10:00.247",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-43529",
"options": [
{
"exploitation": "active"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-18T04:55:16.426232Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-17T21:16:11.570",
"references": [
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125884"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125885"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125886"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125889"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125890"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125891"
},
{
"source": "product-security@apple.com",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"url": "https://support.apple.com/en-us/125892"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"tags": [
"US Government Resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-43529"
}
],
"sourceIdentifier": "product-security@apple.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-416"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
| Vendor project vendor_project | CISA Known Exploited Vulnerabilities | Applereceipt
What the source handed over{
"cveID": "CVE-2025-43529",
"cwes": "CWE-416",
"dateAdded": "2025-12-15",
"dueDate": "2026-01-05",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://support.apple.com/en-us/125884 ; https://support.apple.com/en-us/125892 ; https://support.apple.com/en-us/125885 ; https://support.apple.com/en-us/125886 ; https://support.apple.com/en-us/125889 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43529",
"product": "Multiple Products",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.",
"vendorProject": "Apple",
"vulnerabilityName": "Apple Multiple Products Use-After-Free WebKit Vulnerability"
} | — |