CVE-2025-43529

Published Dec 17, 2025

Last updated 3 months ago

Exploit knownCVSS high 8.8
WebKit
Zero-day
Mobile device

Overview

Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 26.2, Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, tvOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Source
product-security@apple.com
NVD status
Analyzed
Products
safari, ipados, iphone_os, macos, tvos, visionos, watchos

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Apple Multiple Products Use-After-Free WebKit Vulnerability
Exploit added on
Dec 15, 2025
Exploit action due
Jan 5, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-416

Social media

Hype score
Not currently trending
  1. Exploit chain analysis! CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 https://t.co/FiR5Qs9oIG

    @Hermes_tooll

    15 Mar 2026

    1177 Impressions

    5 Retweets

    21 Likes

    6 Bookmarks

    0 Replies

    0 Quotes

  2. Analysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari - iOS 26.1 https://t.co/Xvnp94lKVC

    @Hermes_tooll

    6 Mar 2026

    4652 Impressions

    8 Retweets

    40 Likes

    35 Bookmarks

    0 Replies

    0 Quotes

  3. https://t.co/bMrWsTYsJ8 🔥 PS5 - CVE-2025-43529: UAF confirmed, ROP gadgets found ✅ Reproducible UAF (10 objects, pattern 1/2) ✅ Base libkernel: 0x0823ef8000 ✅ ROP gadgets: pop rdi/rsi/rdx/rax, syscall ✅ Socketpair thread sync functional ✅ Tests T-001 to T-011 pa

    @marcchoc934

    2 Mar 2026

    6334 Impressions

    12 Retweets

    94 Likes

    11 Bookmarks

    6 Replies

    0 Quotes

  4. https://t.co/Cra4E2RB7u 🔥 PS5 - CVE-2025-43529: UAF confirmed, ROP gadgets found ✅ Reproducible UAF (10 objects, pattern 1/2) ✅ Base libkernel: 0x0823ef8000 ✅ ROP gadgets: pop rdi/rsi/rdx/rax, syscall ✅ Socketpair thread sync functional ✅ Tests T-001 to T-011 pa

    @marcchoc934

    2 Mar 2026

    47 Impressions

    1 Retweet

    3 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  5. https://t.co/ZqIwr5ukVa CVE-2025-43529: A use-after-free CVE-2025-14174: An out-of-bounds PARTAIL

    @K1llah03z

    2 Mar 2026

    96 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. New iPhone patches just dropped - lots of fixes including a zero-day malware implant vulnerability that’s already being exploited. CVE-2025-14174 and CVE-2025-43529 are the in-the-wild RCE holes. You’re looking for version 26.3 *after* the update. Enjoy! https://t.co/CArVRA

    @duckblog

    12 Feb 2026

    181 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  7. I hope one day new PS4 webkit exploit on firmware 10.00 and higher finally see a day to abolish PS Vue and BD-JB Example vulnerability that missed on : CVE-2025-14174 CVE-2025-43529

    @MHasyimy

    7 Feb 2026

    174 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Top 5 Trending CVEs: 1 - CVE-2026-21509 2 - CVE-2026-22812 3 - CVE-2026-0755 4 - CVE-2025-43529 5 - CVE-2026-1281 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    2 Feb 2026

    192 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  9. A carefully structured, tiered root cause analysis for CVE-2025-43529 (JSC UAF). Spent quite some time refining the structure to make the reasoning explicit and readable. Shoutout to @jir4vv1t for his detailed analysis and exploit. https://t.co/nGiwxIv2aM

    @bjrjk

    1 Feb 2026

    6046 Impressions

    27 Retweets

    100 Likes

    45 Bookmarks

    0 Replies

    0 Quotes

  10. Top 5 Trending CVEs: 1 - CVE-2025-43529 2 - CVE-2026-1281 3 - CVE-2026-24858 4 - CVE-2024-12084 5 - CVE-2026-24061 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    1 Feb 2026

    187 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Top 5 Trending CVEs: 1 - CVE-2025-43529 2 - CVE-2026-24858 3 - CVE-2025-8088 4 - CVE-2025-15467 5 - CVE-2025-23049 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    29 Jan 2026

    137 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Analysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari - iOS 26.1 https://t.co/NgXP3RfzuE https://t.co/ZcGzBe18Tk

    @ZeeJailbreak

    28 Jan 2026

    4053 Impressions

    10 Retweets

    49 Likes

    15 Bookmarks

    0 Replies

    0 Quotes

  13. PS4 homebrew community should take a look at CVE-2025-43529(new high severity webkit bug), PS Vue is a fuss so much need backup-restore for not jailbroken, and already jailbroken using bd-jb or pppwn can just install PS Vue retail .pkg, but still need psn activated profile.

    @MHasyimy

    27 Jan 2026

    130 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. This exploit code for CVE-2025-43529 and CVE-2025-14174 has been publicly available on GitHub for two weeks, yet VT still shows 0 detections—pretty interesting. https://t.co/BpdrvbpyyS https://t.co/yfZfqchL7C

    @jq0904

    27 Jan 2026

    4962 Impressions

    12 Retweets

    71 Likes

    36 Bookmarks

    2 Replies

    0 Quotes

  15. 🚨 January Linux Patch Wednesday: 918 vulns fixed (616 kernel), 3 exploited (telnetd CVE-2026-24061, Safari CVE-2025-43529, Chromium CVE-2025-14174) + 97 with public exploits. #LinuxPatchWednesday #Linux #Vulristics ➡️ https://t.co/bxPByH2r6f https://t.co/35uge0Gkbg

    @leonov_av

    24 Jan 2026

    133 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🧵 Exploit chain analysis! CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) leads to iOS Safari compromise. 🔥 #Exploit #Web #iOS #CyberSecurity https://t.co/6Zs107sM6s

    @TheExploitLab

    24 Jan 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB): https://t.co/aJog2aUPA7 Vulnerable: iOS ≤26.1 (incl. 17.x–26.1) Patched: iOS 26.2+ Tested on iPhone 11 Pro Max / iOS 26.1 – expect crashes galore! (GC races + PAC issues)

    @hermes_tool1

    24 Jan 2026

    5762 Impressions

    11 Retweets

    93 Likes

    39 Bookmarks

    2 Replies

    0 Quotes

  18. Top 5 Trending CVEs: 1 - CVE-2025-54957 2 - CVE-2026-21962 3 - CVE-2025-43529 4 - CVE-2026-0629 5 - CVE-2017-9506 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    22 Jan 2026

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 🚨 Critical iOS/iPadOS WebKit Zero-Days Put iPhones at Risk of Silent Takeover — Patch Now Apple confirmed two WebKit vulnerabilities (CVE-2025-43529, CVE-2025-14174) that can enable “no warning” compromise through malicious web content, potentially exposing passwords and

    @ThreatSynop

    20 Jan 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Ocak 2026 itibarıyla gündemde olan CVE-2025-43529 ve CVE-2025-14174 kodlu açıklar, "paralı casus yazılımlar" (Pegasus vb.) tarafından iPhone kullanıcılarını hedef almak için kullanılan oldukça tehlikeli iki güvenlik açığıdır. İşte bu saldırı sürecinin ad

    @haydar_beklemez

    20 Jan 2026

    15 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  21. iOS Exploit Chain PoC Alert! @zeroxjf dropped analysis + PoC for CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB): https://t.co/hrWK1DEJHg Vulnerable: iOS ≤26.1 (incl. 17.x–26.1) Patched: iOS 26.2+ Tested on iPhone 11 Pro Max / iOS 26.1 – expect crashes galore! (

    @ZeeJailbreak

    20 Jan 2026

    19994 Impressions

    46 Retweets

    248 Likes

    128 Bookmarks

    11 Replies

    1 Quote

  22. 苹果最近又爆了两个漏洞 分别是 CVE-2025-43529 和 CVE-2025-14174 最近怎么回事,苹果老出漏洞 https://t.co/qsyxRj7XGe

    @annitoBtc

    19 Jan 2026

    488 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  23. Exploit chain analysis: CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB). Targets iOS Safari. Deep dive into the bugs & exploitation. https://t.co/aJog2aUPA7 #exploit #infosec #iOS #webkit #browsersecurity

    @hermes_tool1

    18 Jan 2026

    2686 Impressions

    9 Retweets

    55 Likes

    30 Bookmarks

    0 Replies

    0 Quotes

  24. 🔓 Exploit chain analysis: CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB). Targets iOS Safari. Deep dive into the bugs & exploitation. #exploit #infosec #iOS #webkit #browsersecurity https://t.co/JkaJJyE9i3

    @TheExploitLab

    16 Jan 2026

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. تحليل سلسلة استغلال تجمع بين CVE-2025-43529 (ثغرة Use-After-Free في WebKit) وCVE-2025-14174 (وصول خارج الحدود في ANGLE) لاستهداف Safari على iOS #الأمن_السيبراني #iOS #WebKit https://t.co/Sk9nqZw4mB

    @fad_777

    15 Jan 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. CISA has added CVE-2025-43529 to its Known Exploited Vulnerabilities catalog, highlighting a critical use-after-free vulnerability in Apple’s WebKit component. This flaw affects multiple Apple operating systems, including iOS, iPadOS, macOS, and potentially other products that

    @ox0ffff

    12 Jan 2026

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. 🍎 CVE-2025-43529 — in-the-wild WebKit 0-day now has public exploit Apple: “extremely sophisticated attack against specific targeted individuals” discovered by Google TAG. WebKit DFG JIT UAF → addrof/fakeobj primitives writeup + PoC: https://t.co/XLQ4cC6hzS #itw #web

    @Wh1teCoon

    7 Jan 2026

    188 Impressions

    0 Retweets

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  28. iOS 26.2 and iPadOS 26.2, along with a security advisory that includes fixes for WebKit vulnerabilities. One bug in the DFG JIT compiler (CVE-2025-43529) s https://t.co/NWZUmUVoRH TELEGRAM FOR BUSSINES : https://t.co/VfmhipXTwz

    @minacrissDev_

    6 Jan 2026

    4244 Impressions

    6 Retweets

    32 Likes

    12 Bookmarks

    0 Replies

    0 Quotes

  29. 🚨 Apple Patches Two Actively Exploited WebKit Zero-Days Linked to “Sophisticated” Targeted Attacks Apple shipped emergency fixes for two WebKit zero-days (CVE-2025-43529, CVE-2025-14174) after reports they were used in “extremely sophisticated” attacks against specific

    @ThreatSynop

    21 Dec 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 🚨📱 Apple WebKit zero-days exploited (CVE-2025-43529 / CVE-2025-14174). Update iOS/iPadOS/macOS/Safari now + enable auto-updates. #MobileSecurity #InfoSec Source: https://t.co/qCRP5isyXm https://t.co/6De04xrSal

    @SecureComputer0

    20 Dec 2025

    81 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. Critical security update for #Fedora 43: webkitgtk 2.50.4 addresses multiple vulnerabilities including CVE-2025-43529 (use-after-free) and several process crash CVEs. Read more: 👉 https://t.co/NJkSuQFRp4 #Security https://t.co/yjOFlmNhkH

    @Cezar_H_Linux

    19 Dec 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. 🚨Chrome & WebKit Zero-Days Hit 3.4 Billion Users This Week Google and Apple coordinated emergency patches for multiple zero-days already exploited in "sophisticated attacks." CVE-2025-14174 (ANGLE out-of-bounds) and CVE-2025-43529 (WebKit memory corruption) credited to Go

    @the_c_protocol

    18 Dec 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. webkit2gtk affected by a Use-After-Free vulnerability (DEBIAN-CVE-2025-43529). Processing malicious content can lead to memory corruption. Monitor for official updates. https://t.co/tEEpDBq4Ae

    @pulsepatchio

    18 Dec 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. WebKit UAF (CVE-2025-43529) JSC DFG JIT missed Phi-merged youngsters during Escape Analysis, thereby allowing to GC an object with a live reference. To exploit: convert UAF to a type confusion, structure mismatch, ARW primitive (eg. synthetic butterfly pointer) @alisaesage htt

    @zerodaytraining

    18 Dec 2025

    3154 Impressions

    8 Retweets

    61 Likes

    29 Bookmarks

    1 Reply

    0 Quotes

  35. WebKit UAF (CVE-2025-43529) JSC DFG JIT missed Phi-sourced youngsters during Escape Analysis, thereby allowing to GC an object with a live reference. To exploit: convert UAF to a type confusion, structure mismatch, ARW primitive (eg. synthetic butterfly pointer) @alisaesage ht

    @zerodaytraining

    18 Dec 2025

    425 Impressions

    1 Retweet

    10 Likes

    1 Bookmark

    1 Reply

    1 Quote

  36. [CVE-2025-43529: HIGH] Critical use-after-free issue fixed in Apple updates for watchOS, Safari, iOS, iPadOS, macOS, visionOS, and tvOS. Processing malicious web content may lead to arbitrary code execution.#cve,CVE-2025-43529,#cybersecurity https://t.co/H6Rk215Pp4 https://t.co/2

    @CveFindCom

    17 Dec 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. devs here we go: Apple zero-day 🚨 CVE-2025-43529 is a WebKit use-after-free actively exploited in the wild. Affects iOS, iPadOS, macOS, Safari, and any app using WebKit. Malicious web content can trigger memory corruption with no extra user interaction, potentially

    @paramdhagia

    17 Dec 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. Apple zero-day 🚨 CVE-2025-43529 is a WebKit use-after-free actively exploited in the wild. Affects iOS, iPadOS, macOS, Safari, and any app using WebKit. Malicious web content can trigger memory corruption with no extra user interaction, potentially leading to code https:/

    @paramdhagia

    16 Dec 2025

    139 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  39. This issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-43529 is a WebKit use-after-free remote code execution flaw that can be exploited by processing maliciously crafted web https:

    @minacrissDev_

    16 Dec 2025

    273 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. iOS 26.2 Security Fixes in iOS 26.2 and iPadOS 26.2 WebKit (multiple fixes, including two actively exploited zero-days) - CVE-2025-43529: Use-after-free issue - Malicious web content could lead to arbitrary code execution; actively exploited in targeted attacks. -

    @0xSoKno

    16 Dec 2025

    211 Impressions

    1 Retweet

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログにGladinet CentreStack and TriofoxのCVE-2025-14611とApple WebKitのCVE-2025-43529を追加。対処期限は通常の1/5。ランサムウェアによる悪

    @__kokumoto

    15 Dec 2025

    833 Impressions

    0 Retweets

    7 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  42. Big updates today: - Apple rushes patches for two exploited WebKit zero-days (CVE-2025-14174 & CVE-2025-43529) tied to a sophisticated Chrome flaw impacting iOS, macOS, Safari & more. Update now! - Rogue Chrome extension with "Featured" badge & 6M users caught spyin

    @ImperialTechSvc

    15 Dec 2025

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. 🛡️ We added Gladinet & Apple vulnerabilities CVE-2025-14611 & CVE-2025-43529 to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/BXihRl42AI

    @CISACyber

    15 Dec 2025

    5685 Impressions

    18 Retweets

    42 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  44. Apple lança atualizações urgentes para corrigir duas zero-days usadas em ataques sofisticados: as falhas CVE-2025-43529 e CVE-2025-14174 afetam o WebKit em iPhones e iPads, exploradas para espionagem direcionada, exigindo atualização imediata dos usuários. https://t.co/ISp0

    @caveiratech

    15 Dec 2025

    43 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  45. Warning: Actively exploited vulnerabilities in #Apple WebKit. CVE-2025-14174 and CVE-2025-43529. Exploitation could lead to arbitrary code execution via malicious web content! Check for the latest updates! #Patch #Patch #Patch More info: https://t.co/CgfPxbCZ4j

    @CCBalert

    15 Dec 2025

    87 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. Vulnerability Alert — Apple WebKit Apple patched two WebKit zero-days (CVE-2025-43529, CVE-2025-14174) exploited in the wild. The flaws can lead to code execution or memory corruption via malicious web content. Update iOS, macOS, Safari, and other Apple devices immediately. ht

    @CloneSystemsInc

    15 Dec 2025

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. Apple, aktif olarak istismar edilen iki WebKit güvenlik açığını yamaladı. CVE-2025-43529 (use-after-free) dahil bu açıklar iOS, macOS, Safari'yi etkiliyor. Hemen güncelleme yapın! #SiberGüvenlik #Apple #Güncelleme https://t.co/hXwLV4vgw9

    @osmanmuratgul

    15 Dec 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. 🚨 Upozorňujeme na aktivně zneužívanou zranitelnost v Apple WebKit, CVE-2025-43529. Jedná se o chybu typu use-after-free v renderovacím enginu WebKit, která umožňuje útočníkovi dosáhnout spuštění libovolného kódu při zpracování speciálně vytvořeného šk

    @GOVCERT_CZ

    15 Dec 2025

    370 Impressions

    2 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  49. Update your Apple devices to fix actively exploited vulnerabilities! (CVE-2025-14174, CVE-2025-43529) https://t.co/d3tbR150CR

    @TheCyberSecHub

    15 Dec 2025

    843 Impressions

    4 Retweets

    8 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. Update your Apple devices to fix actively exploited vulnerabilities! (CVE-2025-14174, CVE-2025-43529): Apple has issued security updates with fixes for two WebKit vulnerabilities (CVE-2025-14174, CVE-2025-43529) that have been exploited as zero-days.… https://t.co/WgeUqs9MMW ht

    @shah_sheikh

    15 Dec 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations