CVE-2025-43368 is a use-after-free vulnerability affecting Apple Safari, iOS, iPadOS, and macOS, where processing maliciously crafted web content can lead to an unexpected Safari crash. Rated Medium with a CVSS score of 4.3, this vulnerability has a network attack vector and low attack complexity, requiring user interaction but only leading to a denial of service. There is currently no evidence of active exploitation, nor are public exploit modules available in Metasploit, Nuclei, or ExploitDB. Apple has addressed this issue with improved memory management in Safari 26, iOS 26, iPadOS 26, and macOS Tahoe 26.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.0CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 26.0CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 26.0CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 26.0CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.