CVE-2025-43343 is a critical memory handling vulnerability affecting Apple's WebKit engine across Safari, iOS, macOS, tvOS, visionOS, and watchOS, as well as webkitgtk and wpewebkit. Processing maliciously crafted web content can lead to an unexpected process crash, with a high likelihood of remote code execution. Rated 9.8 CRITICAL, this vulnerability can be exploited remotely over the network with low complexity and no user interaction, resulting in high impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code is unavailable, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.0CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 26.0CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 26.0CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 26.0CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
< 26.0CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.