- Description
- A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
- Source
- product-security@apple.com
- NVD status
- Modified
- Products
- safari, ipados, iphone_os, tvos, visionos, watchos
CVSS 3.1
- Type
- Secondary
- Base score
- 4.3
- Impact score
- 1.4
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
- Severity
- MEDIUM
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-416
- Hype score
- Not currently trending
Three vulnerabilities fixed in macOS Tahoe 26.1: https://t.co/TitY8KUoT3 Webkit (JavaScriptCore): CVE-2025-43457: UAF vulnerability during DFG CSE phase graph node substitution CVE-2025-43432: UAF vulnerability during WASM function parsing CoreText: CVE-2025-43445: OOB access
@hosselot
10 Dec 2025
2856 Impressions
3 Retweets
26 Likes
6 Bookmarks
0 Replies
0 Quotes
🔴USN-7914-1 - WebKitGTK CVEs Enable Browser Code Execution Ubuntu patched seven critical WebKitGTK vulnerabilities enabling arbitrary code execution via malicious web content. CVE-2025-43432 through CVE-2025-43392 span use-after-free bugs, memory corruption, and type confusi
@the_c_protocol
9 Dec 2025
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Apple Safari JavaScriptCore Wasm Function Parsing Use-After-Free Remote Code Execution Vulnerability (CVE-2025-43432) #Apple #AppleSafari #CVE202543432 #CyberSecurity #RemoteCodeExecutionVulnerability https://t.co/PqV1Y9FQkS https://t.co/5QxoOVejc2
@SystemTek_UK
17 Nov 2025
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Apple Security Update - November 4, 2025 Apple just dropped patches for 50 vulnerabilities across macOS, iOS, iPadOS, Safari, watchOS, tvOS, and visionOS. WebKit Crashes Everywhere - Multiple use-after-free issues in Safari/WebKit (CVE-2025-43432, CVE-2025-43435,
@gothburz
4 Nov 2025
424 Impressions
0 Retweets
3 Likes
2 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"matchCriteriaId": "CFF118CE-3F13-43BE-B250-5579E1C842EB",
"versionEndExcluding": "26.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6D51AEDC-9086-4010-B3BF-C652D65D09C8",
"versionEndExcluding": "26.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3981A7BE-BC98-4C6F-AE38-D68839368925",
"versionEndExcluding": "26.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "290E0D29-CB5B-45A7-9FE3-FD2030B1D1A4",
"versionEndExcluding": "26.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7DFD3616-65CA-4E5C-849C-3C20ACBCB610",
"versionEndExcluding": "26.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "9F9D7F76-13FB-407C-94E5-221B93021568",
"versionEndExcluding": "26.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]