cbcvebase.
CVE-2025-43529
published 2025-12-17

CVE-2025-43529: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS…

PriorityP189high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-01-05
Exploited in the wild
EPSS
8.58%
94.5th percentile
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
appleios_18.7.3_and_ipados
appleios_26.2_and_ipados
appleios_26.3_and_ipados
appleipados< 18.7.318.7.3
appleipados< 26.326.3
appleipados>= 26.0 < 26.226.2
appleiphone_os< 18.7.318.7.3
appleiphone_os< 26.326.3
appleiphone_os>= 26.0 < 26.226.2
applemacos< 26.326.3
applemacos>= 26.0 < 26.226.2
applemacos_tahoe
applemacos_tahoe
applesafari< 26.226.2
applesafari
appletvos< 26.226.2
appletvos< 26.326.3
appletvos
appletvos
applevisionos< 26.226.2
applevisionos< 26.326.3
applevisionos
applevisionos
applewatchos< 26.226.2
applewatchos< 26.326.3

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-43529 is a WebKit use-after-free vulnerability triggered by processing maliciously crafted web content, enabling arbitrary code execution; detection should focus on WebKit/Safari process crashes or unexpected code execution originating from web content rendering on Apple platforms (iOS before iOS 26, macOS, tvOS, watchOS, visionOS, Safari).
  • CVE-2025-43529 was exploited in conjunction with CVE-2025-14174 (ANGLE/WebGL memory corruption in Chrome/WebKit) as part of the same sophisticated targeted attack chain; detections should consider chained exploitation of both CVEs delivered via malicious web content.
  • ·Apple provided no technical details on the exploitation method or threat actor; the attack is described only as 'extremely sophisticated' and 'targeted,' limiting the ability to build precise behavioral detections without further threat intelligence.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.